 
                                                
    
    
    
    
            Excited to release a tool I've been working on lately - ShareFiltrator
ShareFiltrator finds credentials exposed in SharePoint/OneDrive via the Search API (_api/search/query) and also automates mass downloading of the discovered items.
Blog: blog.fndsec.net/2025/04/02/b...
               
            
            
                02.04.2025 11:30 β π 1    π 0    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
            
    
    
    
    
            Thank you! Bofhound has been incredible for us!
               
            
            
                26.11.2024 04:52 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                         
                                                
    
    
    
    
            Excited to share a tool I've been working on - ShadowHound.
ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them.
blog.fndsec.net/2024/11/25/s...
               
            
            
                25.11.2024 12:25 β π 32    π 10    π¬ 0    π 1                      
            
         
            
        
            
        
            
        
            
        
            
        
            
            
            
            
            
    
    
            
            
            
                YouTube video by TrustedSec
                TrustedSec Tech Brief - November 2024
            
         
    
    
            TrustedSec Tech Brief 
00:30 - NTLM Hash Disclosure Zero-Day
01:45 - Task Scheduler Vulnerability
02:30 - Exchange Server Issues
03:15 - AD Certificate Services Flaw
04:00 - Vulnerability Breakdown
04:45 - Palo Alto Zero-Day
05:30 - FortiGate VPN Update
www.youtube.com/watch?v=3mSD...
               
            
            
                19.11.2024 16:32 β π 61    π 21    π¬ 3    π 1                      
            
         
            
        
            
            
            
            
            
    
    
            
                             
                        
                Last Week in Security (LWiS) - 2024-11-18
                Arc browser RCE (@RenwaX23), more Fortinet woes (@SinSinology), PowerHuntShares v2 (@_nullbind), make_token_cert (@freefirex2), BOFs without DFR (@netbiosX), and more!
            
        
    
    
            Arc browser RCE, more Fortinet woes (@sinsinology.bsky.social), PowerHuntShares v2, make_token_cert, BOFs without DFR (@netbiosx.bsky.social),  and more!
blog.badsectorlabs.com/last-week-in...
               
            
            
                19.11.2024 05:25 β π 5    π 2    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            AdobeFips - Adobe Reader Lolbin
www.hexacorn.com/blog/2024/11...
               
            
            
                16.11.2024 18:12 β π 9    π 5    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            Beyond good olβ Run key, Part 144
www.hexacorn.com/blog/2024/11...
               
            
            
                15.11.2024 22:17 β π 23    π 10    π¬ 1    π 0                      
            
         
    
         
        
            
        
                            
                    
                    
                                            π₯οΈ Where innovation strategy meets cybersecurity
π΅οΈββοΈ Penetration Testing
π² AppSec Tools
πΌ Cyber Risk Regulations
π Infosec Education
https://linktr.ee/areenzor
                                     
                            
                            
                    
                    
                                            Trend Zero Day Initiativeβ’ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
                                     
                            
                    
                    
                                            Offensive Security | Red Teamer | Learning MalDev | OSEP | CRTL | OSWP | CRTO | CRTE | CRTP | CESP-ADCS | eJPT
http://m4lici0u5.com
                                     
                            
                    
                    
                                            Tinkerer, security geek, recovering entrepreneur, full professor at www.polimi.it, frequent flyer, private pilot, and generic pundit. He/Him π³οΈβπβ©
For aviation follow me on Instagram, same id!
                                     
                            
                    
                    
                                            0day Researcher @ ββββββββββββ  / Baker / 0wl
// I post random things on here
                                     
                            
                    
                    
                                    
                            
                    
                    
                                            Principal Security Researcher at GreyNoise. https://skullsecurity.org
Mostly post about work stuff, maybe some improv stuff and maybe even magic some day. Seattle-based (originally Canadian), queer, cybersecurity nerd.
(He/him)
                                     
                            
                    
                    
                                            Staff Security Engineer at GoFundMe
@Jhyp3 on Twitter
                                     
                            
                    
                    
                                            CTO @TrustedSec.com | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
                                     
                            
                    
                    
                                            Security researcher/programmer β Managing director @ HexArcana β @DragonSectorCTF founder β he/him
                                     
                            
                    
                    
                                            offensive security - windows internals - reverse engineering | X: https://x.com/splinter_code | Mastodon: https://infosec.exchange/@splinter_code | GitHub: https://github.com/antonioCoco | Blog: https://splintercod3.blogspot.com/
                                     
                            
                    
                    
                                            Tech enthusiasts, offensive cybersecurity professional, AI student
                                     
                            
                    
                    
                                            A penetration tester living in Scotland. 
I am also into video games, home recording music, guitars, sci-fi, the concept of Scotland getting an independence vote again, and nachos. I like nachos.
                                     
                            
                    
                    
                                            CyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
                                     
                            
                    
                    
                                            BallisKit provides tooling and services to professional Pentesters & Red Teams. 
We develop  MacroPack Pro and ShellcodePack. 
www.balliskit.com
                                     
                            
                    
                    
                                            hacker, poster, weird machine mechanic
https://chompie.rip
                                     
                            
                    
                    
                                            ζεΏ / Antiquarian @ IBM Adversary Services / Ex-TORE βοΈπ¦
 / I rewrite pointers and read memory / AI Psychoanalyst / Teaching 
at labs.calypso.pub
                                     
                            
                    
                    
                                            Self Hating Red Teamer - Legitimate Business Practice
π¦: @4lex
                                     
                            
                    
                    
                                            Network Security | Hacker | WIRED25 2020 | CTI-League Founder | Security Researcher