Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile
Panos Gkatziroulis 🦄

@netbiosx

Red/Purple Teamer | Blogger | Director @pentestlabltd | Mod @ reddit.com/r/purpleteamsec | discord.gg/rR6FJBH

ID: 457095704

linkhttp://ipurple.team calendar_today07-01-2012 01:06:39

13,13K Tweet

24,24K Takipçi

796 Takip Edilen

Ricardo Ruiz (@ricardojoserf) 's Twitter Profile Photo

I wrote a short post about how you only need the NtReadVirtualMemory address for dynamic API resolution, plus how you could use a vulnerable binary to leak its address (and you would not have GetProcAddress, GetModuleHandle or LoadLibrary in the IAT) - github.com/ricardojoserf/…

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

ControlSTUDIO - an adversary simulation framework made fully in Go, with support for malleable command and control (C2) profiles. github.com/zarkones/Contr… #redteam

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

FACADE: a high-precision deep-learning-based machine learning system used in a number of applications across Google. It is used as a last line of defense against insider threats, as an ACL recommendation system, and as a way to detect account compromise github.com/google/facade

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

ETWLocksmith - A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows registry github.com/olafhartong/ET…

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

SpearSpray - an advanced password spraying tool designed specifically for AD environments. It combines user enumeration via LDAP with intelligent pattern-based password generation to perform controlled and stealthy password spraying attacks over Kerberos. github.com/sikumy/spearsp…

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

DllShimmer - Weaponize DLL hijacking easily. Backdoor any function in any DLL without disrupting normal process operation github.com/Print3M/DllShi…

David (@dmcxblue) 's Twitter Profile Photo

Back from PTO and back on my Azure vulnerable lab project Function Apps, Runbooks, VMs, DBs, SPNs & more. Built to learn Azure and sharpen my Red Team. Works on Pay-As-You-Go (no P1/P2 needed). Hoping others find it useful! #redteam github.com/dmcxblue/Azure…

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

Checks to see which drivers from loldrivers.io are not blocked by the current HVCI blocklist on the system github.com/trailofbits/HV…

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows Filtering Platform (WFP) github.com/0xJs/BlockEDRT…

Print3M // SecTube.tv (@print3m_) 's Twitter Profile Photo

I'm releasing my new tool: DllShimmer 🔥 Weaponize DLL hijacking easily. github.com/Print3M/DllShi… - backdoor any function, no reverse engineering - all functions proxied, no program crash - built-in debug info and mutex to every function - more... #redteam #malware #security

I'm releasing my new tool: DllShimmer 🔥 Weaponize DLL hijacking easily.

github.com/Print3M/DllShi…

- backdoor any function, no reverse engineering
- all functions proxied, no program crash
- built-in debug info and mutex to every function
- more...

#redteam #malware #security
Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

🎯 As a new article is being prepared, a quick recap to the what it has been posted the last month! ⭐️ ipurple.team/2025/07/28/bad… ⭐️ ipurple.team/2025/08/04/lat… ⭐️ ipurple.team/2025/08/12/act…

🎯 As a new article is being prepared, a quick recap to the what it has been posted the last month!
⭐️ ipurple.team/2025/07/28/bad…
⭐️ ipurple.team/2025/08/04/lat…
⭐️ ipurple.team/2025/08/12/act…
Steven (@0xthirteen) 's Twitter Profile Photo

I wanted to find out if you could start the WebClient service remotely, so I ended up digging into it specterops.io/blog/2025/08/1…