geech's Avatar

geech

@captaingee.ch.bsky.social

cybercrime connoisseur && exploitz engineering enthusiast | synapse fanboy | second breakfast enthusiast

107 Followers  |  127 Following  |  35 Posts  |  Joined: 26.05.2023  |  1.9771

Latest posts by captaingee.ch on Bluesky

Preview
ctfd_first_blood_bot.py GitHub Gist: instantly share code, notes, and snippets.

threw together a quick first blood discord bot for CTFd for an event im hosting next week gist.github.com/captainGeech...

02.08.2025 22:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

working on a simple web chal and was too lazy to write the ui myself, gemini almost turned this into a second challenge ๐Ÿ™ƒ

age of llm==age of free xss?

29.07.2025 23:22 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Being in tech and having a single modicum of critical thinking is just screaming "this isn't what LLMs are designed for" over and over as people shove a bunch of word predictors into critical decision making processes because some glorified used car salesmen told them it would fix all their problems

23.07.2025 18:10 โ€” ๐Ÿ‘ 3961    ๐Ÿ” 1368    ๐Ÿ’ฌ 52    ๐Ÿ“Œ 33
Preview
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud Blog A financially-motivated threat actor is targeting fully patched end-of-life SonicWall devices to deploy a backdoor known as OVERSTEP.

I wrote a new blog with Mandiant IR + FLARE on some new intrusion activity by a group we track as UNC6148, likely using a mix of n-day and 0-day exploits to compromise SonicWall SMA 100 series VPN appliances. They have some nifty post-exploitation tooling as well

cloud.google.com/blog/topics/...

16.07.2025 14:44 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

shuka should give a talk at anticon

10.07.2025 23:15 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Signal sticker pack metadata is fun

signal.art/addstickers/...

10.07.2025 22:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
a group of men standing on a race track with a yellow sign that says huuuulkkkkk ALT: a group of men standing on a race track with a yellow sign that says huuuulkkkkk

the true GOAT

06.07.2025 20:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

(this is even more egregious and frustrating when you do it for internal tools)

05.07.2025 15:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

if you need to use AggresIve styling, dark patterns, popups, and anti-user defaults to get people to use your new features, maybe they are not good features :)

05.07.2025 15:40 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

there is something so satisfying about writing rop chains, idk what it is, just a super fun puzzle

01.07.2025 00:57 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Phone unlocking firm Cellebrite to acquire mobile testing startup Corellium for $170M | TechCrunch Cellebrite said the deal will help with the "accelerated identification of mobile vulnerabilities and exploits."

Picked a bad day to wear my Corellium t-shirt smh โ˜ ๏ธ

techcrunch.com/2025/06/05/p...

05.06.2025 19:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.

I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it.

cloud.google.com/blog/topics/...

07.05.2025 14:13 โ€” ๐Ÿ‘ 18    ๐Ÿ” 14    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

why more JS engines don't have a native bogosort implementation is truly a wonder

26.04.2025 17:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

greetings fellow windows 11 upgrade refuser

01.04.2025 19:30 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

"And this is why using AppContainer with a packaged app is easier"

screw you microsoft i do what i want

learn.microsoft.com/en-us/window...

01.04.2025 19:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
winnativetemplate/Makefile at main ยท captainGeech42/winnativetemplate Template repo for using Make to compile simple win32/MSVC code - captainGeech42/winnativetemplate

if you despise using Visual Studio as much as i do, here you go

github.com/captainGeech...

31.03.2025 22:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Too many OPSEC experts out there, Iโ€™m an OOPSEC expert. Lmk if you need help adding The Atlantic to YOUR pc small group chats. Signal and more!

27.03.2025 17:12 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

hey microsoft, hot take, what if you didnt push ads for random games in your fucking operating system as notifications

09.03.2025 22:15 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
a child is doing a handstand on a swing over a puddle of water ALT: a child is doing a handstand on a swing over a puddle of water

diaphora vs vmware-vmx

meanwhile, me watching:

07.03.2025 02:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

arrested development season 1 is the true peak of comedy

04.03.2025 00:08 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

lmfao this worked perfectly. thank you to "brute force to make up for my lack of brain cells"

02.03.2025 11:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

reverse engineering and thinking about reducing problem spaces to hit vulnerable code paths is hard.

fuzzing however, is both "easy" and "fast" - lazy ftw

(may work, may not work, we'll see. need a @digitalocean.com sponsorship lol)

02.03.2025 02:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

my arch laptop hasnt crashed once since districtcon and has been busy since then, so im just going to chalk it up to "cold dark room is scary to gnome" and pretend this never happened

see you at the next talk where it will inevitably happen again

01.03.2025 20:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Department of Government Efficiency

23.02.2025 01:10 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Now that my @districtcon.bsky.social talk is over, here is the official open-source release of implant.js! I think this represents a notable advancement in the state of the art for modular CNO implant frameworks.

Lots of detection info included as well.

github.com/captainGeech...

22.02.2025 17:23 โ€” ๐Ÿ‘ 13    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

today i used a debugger so bad that you have to nop sled it when inserting breakpoints to ensure they get hit in the place you want.

yes i wrote the debugger but thats besides the point

18.02.2025 01:52 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

If you want your own IDA sticker, come find me @districtcon.bsky.social ;)

16.02.2025 13:51 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
CL0P Ransomware : Latest Attacks - CYFIRMA INTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The...

This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it.
LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis.
www.cyfirma.com/research/cl0...

15.02.2025 22:29 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

c plus plus, more like c plus sucks

14.02.2025 00:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@captaingee.ch is following 20 prominent accounts