evil_enigma's profile picture. CyberSecurity Professional

EvilEnigma

@evil_enigma

CyberSecurity Professional

academy.hackthebox.com/achievement/80… #hackthebox #htbacademy #cybersecurity If you are keen to delve into multi step attacks mixing XHR, Fetch to priv esc over CORS misconfiguration or exfil data from an XSS. This one takes it to next level. Advanced XSS and CSRF labs!


hackthebox.com/achievement/ma… finally popped Cerberus! What a beast of a windows challenge this was.

Who's a good boy? 🦴 A new #HTB Seasons Machine is coming up! Cerberus created by @TheCyberGeek19 will go live on 18 March 2023 at 19:00 UTC. Extension will be retired! ✔️ Hard ✔️ Windows → Choose your Machine and start #hacking: hackthebox.com/machines #HackTheBox #HTBSeasons

hackthebox_eu's tweet image. Who's a good boy? 🦴
A new #HTB Seasons Machine is coming up! Cerberus created by @TheCyberGeek19 will go live on 18 March 2023 at 19:00 UTC. Extension will be retired!
✔️ Hard
✔️ Windows
→ Choose your Machine and start #hacking: hackthebox.com/machines
#HackTheBox #HTBSeasons


EvilEnigma hat repostet

A lot has been said about removing hooks and kernel callbacks to stop an EDR from detecting malicious activity. What if we could terminate the process completely? Well ...we can. Check this out: spikysabra.gitbook.io/kernelcactus/


EvilEnigma hat repostet

Stop caring about what others think…


EvilEnigma hat repostet

Me at the start of every red team: * I will report as I go * I will take the most comprehensive notes ever seen * I will not rely on C2 logs * screen cap all the things ..... Me at the end of every red team: * well shit


Learning to use #terraform for #redteam? Here is my simple script that demonstrates its common capabilities. shorturl.at/kpr02


EvilEnigma hat repostet

In this post, I discuss one key difference in the thinking between sophisticated adversaries and many of the red teams that try to simulate them, as well as what that means for tradecraft and tooling. jackson_t.gitlab.io/it-depends.html

Jackson_T's tweet image. In this post, I discuss one key difference in the thinking between sophisticated adversaries and many of the red teams that try to simulate them, as well as what that means for tradecraft and tooling.

jackson_t.gitlab.io/it-depends.html

EvilEnigma hat repostet

One lesson that I see to folks new and old in the industry struggle with is: Remaining humble and recognizing that you are always learning and need to continue to learn from others. Trust me, you don't know everything, and never will. Be humble, kind, and help others.


EvilEnigma hat repostet

CTF at DEFCON29 @RedTeamVillage_ is about to start, so we decided to give out a 15% discount on all our available courses. Use the coupon below before Aug 8th: institute.sektor7.net/?coupon=DEFCON… Happy hacking at #DEFCON29! #hacktheplanet #redteam #CyberSecurity

SEKTOR7net's tweet image. CTF at DEFCON29 @RedTeamVillage_ is about to start, so we decided to give out a 15% discount on all our available courses.

Use the coupon below before Aug 8th:
institute.sektor7.net/?coupon=DEFCON…

Happy hacking at #DEFCON29!

#hacktheplanet #redteam #CyberSecurity

EvilEnigma hat repostet

The latest Red Team Ops updates have dropped. Read about the changes here: zeropointsecurity.co.uk/blog/red-team-…


This is a fantastic Mindmap for ACE abuse.

Active Directory ACEs abuse mindmap

_nwodtuhs's tweet image. Active Directory ACEs abuse mindmap


EvilEnigma hat repostet

👀👀👀

_ZeroPointSec's tweet image. 👀👀👀

EvilEnigma hat repostet

👀👀👀


EvilEnigma hat repostet

3000 follower #Giveaway 🎉 🎁1-month access to @PentesterLab PRO ($19.99) 🎁1-month access to @_RastaMouse Red Team Ops Course (£399) tag someone for whom this would be life-changing + why. and yes you can @ yourself 🤓 winner will be revealed in 24 hours! #bugbounty

huntr_ai's tweet image. 3000 follower #Giveaway 🎉

🎁1-month access to @PentesterLab PRO ($19.99)
🎁1-month access to @_RastaMouse Red Team Ops Course (£399)

tag someone for whom this would be life-changing + why.

and yes you can @ yourself 🤓

winner will be revealed in 24 hours!

#bugbounty

EvilEnigma hat repostet

We've just released our research, tooling and datasets on contextual content discovery, if you're interested in improving your content discovery skills, you should check it out! blog.assetnote.io/2021/04/05/con…

assetnote.io

Contextual Content Discovery: You've forgotten about the API endpoints

Contextual Content Discovery: You've forgotten about the API endpoints


EvilEnigma hat repostet

Companies pay $$$ to get an expensive solution and don’t actually have people to test to see it works. Then I walk in with a web_delivery meterpreter and are surprised that it gets through it. Invest in people, not products. Same old story over and over again.


EvilEnigma hat repostet

Sometimes we don't feel great or amazing. Often it has nothing to do with anything in particular. But our mind will keep trying to find a problem. And when our mind seeks something, it often finds it.


One of my long pending personal goals was to improve my skill set in exploit development. I’m finally starting my journey today with Cracking The Perimeter (CTP) course and hopefully #OSCE soon! Thank you @offsectraining for making these courses.


EvilEnigma hat repostet

The deck and webinar recording from @jaredcatkinson's and my talk yesterday are now available! Recording: specterops.zoom.us/rec/share/v81J… Deck: bit.ly/2Wk9bAm

_wald0's tweet image. The deck and webinar recording from @jaredcatkinson's and my talk yesterday are now available!

Recording: specterops.zoom.us/rec/share/v81J…

Deck: bit.ly/2Wk9bAm

Loading...

Something went wrong.


Something went wrong.