1.3K Followers
228 Following
491 Posts
Author of PayloadsAllTheThings 📖 & SSRFmap 🐛
Twitterhttps://twitter.com/pentest_swissky
Bloghttps://swisskyrepo.github.io/
DLS 2024 - RedTeam Fails - "Oops my bad I ruined the operation", a story on how to fail a red team assessment 🦖
https://swisskyrepo.github.io/Drink-Love-Share-Rump/
DLS 2024 - RedTeam Fails - “Oops my bad I ruined the operation”

Red Team Fails - “Oops my bad I ruined the operation”, a story on how to fail a red team assessment. TLDR: Recently I had the pleasure to give a rump during the “Drink Love Share” meet organized by TheLaluka. This blog post will delve deeper into the topic. This rump told the tale of a little Dino starting in the red team industries.

Swissky’s adventures into InfoSec World !
For #redteaming engagements it would be nice to have access to a large collection of breach and leak details. How do you keep up with that? Any recommendations?
RT @RET2_pwn
Exciting news!📢I'm breaking down the Mimikatz modules into a COFF Object, which will make EDRs a non-issue using some clever evasion techniques. Keep an eye out for MimiCOFF, releasing on November 8th! Feel free to request a specific module. #cybersecurity #redteam
Peace Out !✌️
Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587)
https://the-deniss.github.io/posts/2023/04/26/avast-privileged-arbitrary-file-create-on-quarantine.html
Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587)

0x00: Introduction

the-deniss.github.io
Stealing GitHub staff's access token via GitHub Actions
https://blog.ryotak.net/post/github-actions-staff-access-token-en/
Stealing GitHub staff's access token via GitHub Actions

(この記事は日本語でも読むことが出来ます。) Disclaimer GitHub is running a bug bounty program on HackerOne, and as part of this program, vulnerability research is permitted by the safe harbor. This article describes a vulnerability that I discovered as a result of my investigation in compliance with the safe harbor criteria and is not intended to encourage unauthorized vulnerability research activities. If you find a vulnerability on GitHub, please report it to GitHub Bug Bounty. TL;DR In the actions/runner repository, which hosts the source

So you think you can block Macros? - Pieter Ceelen
https://outflank.nl/blog/2023/04/25/so-you-think-you-can-block-macros/
So you think you can block Macros? | Outflank

blog about macro blocking/signing, attacker/red team work arounds and further mitigations. Macro signing, message bar & Excel add-ins

Outflank
Capturing the Flag with GPT-4

RT @th1b4ud
Si vous avez envie de participer à l'émission envoyez moi un DM ! https://twitter.com/crontalkfr/status/1653290654645080064
Crontalk on Twitter

“🎙️Retrouvez la chronique de Alain Mavurk, pentester chez @Intrinsec, sur #Crontalk. Il nous détaille son métier et son quotidien. 👉 https://t.co/Wregtb1qwb”

Twitter

RT @fr0gger_
🤗I've written a book! Let me introduce you "Visual Threat Intelligence"

You can register now to stay updated on its release and learn more about it in the link below. I really hope you'll like it! 🥹 #VisualThreatIntelligence #infosec #threatintel

👉https://store.securitybreak.io/threatintel

Introducing BloodHound 4.3 — Get Global Admin More Often

Thank you to Hugo Vincent for his AzureHound contribution which adds app role assignment enumeration, enabling the MS Graph attack path feature. Thank you to Hugo as well for his BloodHound PR to…

Posts By SpecterOps Team Members