Soheil (@soheilsec) 's Twitter Profile
Soheil

@soheilsec

Red Team | Adversary simulation
CRTL ¦ CRTO ¦ MCRTA ...

ID: 82490775

linkhttps://www.youtube.com/@soheilsec calendar_today14-10-2009 23:59:27

4,4K Tweet

2,2K Followers

434 Following

ACE Responder (@aceresponder) 's Twitter Profile Photo

FREE reverse engineering module now available! Learn assembly fundamentals - perfect for beginners. • Hands-on debugging with real examples • Web based: no downloads, installs, or VMs Start reversing here 👇

Steve S. (@0xtriboulet) 's Twitter Profile Photo

I put a BOF loader in a BOF so that you can run BOFs from a BOF. If you've had issues getting a BOF to work with CS's BOF loader in the past, you now have a drop-in way to get a little bit more compatibility. github.com/0xTriboulet/In…

S3cur3Th1sSh1t (@shitsecure) 's Twitter Profile Photo

Remotely enable the EFS service for Win11 systems? No problem with rpcping. Just worked for me from remote with a low privileged user. 🧐

Remotely enable the EFS service for Win11 systems? No problem with rpcping. Just worked for me from remote with a low privileged user. 🧐
Andrea Pierini (@decoder_it) 's Twitter Profile Photo

Coercing machine authentication on Windows 11 /2025 using the MS-PRN/PrinterBug DCERPC edition, since named pipes are no longer used. Kerberos fails in this case due to a bad SPN from the spooler, forcing NTLM fallback.

Coercing machine authentication on Windows 11 /2025 using the MS-PRN/PrinterBug DCERPC edition, since named pipes are no longer used.
Kerberos fails in this case due to a bad SPN from the spooler, forcing NTLM fallback.
🕳 (@sekurlsa_pw) 's Twitter Profile Photo

Nice blog with BOF tool release “BadTakeover” & SharpSuccessor (github.com/logangoins/Sha…) update. Needed privs for account takeover: 📚OU: CreateChild 🎯Target: GenericWrite/WriteProperty or msDS-SupersededManagedAccountLink and msDS-SupersededServiceAccountState 🖥️ DC: Win 2025

Nice blog with BOF tool release “BadTakeover” & SharpSuccessor
(github.com/logangoins/Sha…) update. 

Needed privs for account takeover:
📚OU: CreateChild
🎯Target: GenericWrite/WriteProperty or
msDS-SupersededManagedAccountLink and msDS-SupersededServiceAccountState
🖥️ DC: Win 2025
freefirex (@freefirex2) 's Twitter Profile Photo

rolled out a bof for getting the dpapi_system key used by mimikatz /system: when ingesting master keys. If that's something you need it's live at github.com/trustedsec/CS-…

rolled out a bof for getting the dpapi_system key used by mimikatz /system: when ingesting master keys.  
If that's something you need it's live at github.com/trustedsec/CS-…
SpecterOps (@specterops) 's Twitter Profile Photo

Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️ ghst.ly/4qtl2rm

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

Remember the CredMarshalInfo trick? If you hadn’t applied the June 2025 patch, CVE-2025-33073 would have been critical. We know that in NTLM local auth, msg 3 is empty:You can drop sign/seal -> from Domain User to DomainAdmin escalation. 😅

Remember the CredMarshalInfo trick? If you hadn’t applied the June 2025 patch, CVE-2025-33073 would have been critical. We know that in  NTLM  local auth, msg 3 is empty:You can drop sign/seal -> from Domain User to DomainAdmin escalation. 😅
Two Seven One Three (@twosevenonet) 's Twitter Profile Photo

EDR-Redir: You can break EDRs/Antivirus from user mode with bind link and cloud minifilter. Because your payload deserves privacy. #antimalware #itsecurity #redteam

EDR-Redir: You can break EDRs/Antivirus from user mode with bind link and cloud minifilter.
Because your payload deserves privacy.
#antimalware #itsecurity #redteam
MDSec (@mdseclabs) 's Twitter Profile Photo

Interested in an alternative approach to sleep masking for you malware? Check-out our latest blog post "Function Peekaboo: Crafting self masking functions using LLVM" by sabotage mdsec.co.uk/2025/10/functi…

Interested in an alternative approach to sleep masking for you malware? Check-out our latest blog post "Function Peekaboo: Crafting self masking functions using LLVM" by <a href="/saab_sec/">sabotage</a> mdsec.co.uk/2025/10/functi…
Lsec (@lsecqt) 's Twitter Profile Photo

I am happy to present the latest blogpost I was working on. It is about enumerating and attacking MSSQL databases from both external and internal perspective. Hope you learn something from it and as always, any feedback is welcomed! r-tec.net/r-tec-blog-mss…

Stephen Fewer (@stephenfewer) 's Twitter Profile Photo

New Metasploit Project aux module in the pull queue for the FortiWeb vuln (no CVE at this time). Based on the PoC captured and posted by Defused, it leverages an auth bypass to create a new local admin account on the target. github.com/rapid7/metaspl…

New <a href="/metasploit/">Metasploit Project</a> aux module in the pull queue for the FortiWeb vuln (no CVE at this time). Based on the PoC captured and posted by <a href="/DefusedCyber/">Defused</a>, it leverages an auth bypass to create a new local admin account on the target. github.com/rapid7/metaspl…
Soheil (@soheilsec) 's Twitter Profile Photo

Attractive folks learn malware analysis. Meanwhile the truly intelligent ones are out there coding digital chaos🗿

Dark Web Informer - Cyber Threat Intelligence (@darkwebinformer) 's Twitter Profile Photo

🚨Cl0p Ransomware Claims 30 Victims 🇸🇦 Al Jomaih Automotive 🇺🇸 Fruit of the Loom 🇺🇸 Frontrol 🇺🇸 Humana 🇺🇸 Oracle 🇺🇸 Abbott Laboratories 🇯🇵 Mazda 🇱🇰 MAS Holdings 🇯🇵 Canon 🇮🇪 Trane Technologies 🇲🇽 Grupo Bimbo 🇺🇸 Bechtel 🇺🇸 Estée Lauder Companies 🇰🇼 Alshaya Group 🇸🇬 Fleetship

🚨Cl0p Ransomware Claims 30 Victims

🇸🇦 Al Jomaih Automotive
🇺🇸 Fruit of the Loom
🇺🇸 Frontrol
🇺🇸 Humana
🇺🇸 Oracle
🇺🇸 Abbott Laboratories
🇯🇵 Mazda
🇱🇰 MAS Holdings
🇯🇵 Canon
🇮🇪 Trane Technologies
🇲🇽 Grupo Bimbo
🇺🇸 Bechtel
🇺🇸 Estée Lauder Companies
🇰🇼 Alshaya Group
🇸🇬 Fleetship
Altered Security (@alteredsecurity) 's Twitter Profile Photo

Black Friday Giveaway & Exclusive Discounts Win FREE access to: • 1 CRTE seat • 1 CETP seat How to participate: 1️⃣ Like this post 2️⃣ Comment which course you’re interested in and why 3️⃣ Repost Winners will be randomly selected and announced on December 2, 2025. Those who’ve

Black Friday Giveaway &amp; Exclusive Discounts

Win FREE access to:
• 1 CRTE seat
• 1 CETP seat

How to participate:
1️⃣ Like this post
2️⃣ Comment which course you’re interested in and why
3️⃣ Repost

Winners will be randomly selected and announced on December 2, 2025.
Those who’ve