Safari ride-style showcase of password spraying tools & techniques with an extra flair for Entra ID-- featuring OpenBullet, MSOLSpray, entraspray, TeamFiltration & hints of FireProx, OmniProx, etc to finally simply rotate IPs low and slow with Tor. Video: youtu.be/oWv50EF0juc
20.10.2025 13:01 β π 3 π 0 π¬ 0 π 0
Another "old but gold" little trick, harkening back to @mubix's blog post waaay back in 2013: "Stealing passwords every time they change" -- creating a Password Filter & adding it to Windows Registry. A clever persistence trick to exfiltrate credz. Video: youtu.be/DhP2Hw-6DgY
16.10.2025 13:01 β π 6 π 0 π¬ 1 π 0
An idea I had some time ago was to create an open-source project with community contributions to centralize different social engineering lure techniques & native GUI tools that could be leveraged for ClickFix... a LOLBins-style site w/ mitigations. Video: youtu.be/UQqsaO5k2M0
07.10.2025 13:01 β π 9 π 2 π¬ 2 π 0
Hex-Rays: State-of-the-Art Binary Code Analysis Tools
Professional binary analysis with IDA Pro disassembler and decompiler. Tools for reverse engineering, malware analysis, and vulnerability research.
And a HUGE thank you to Hex-Rays for sponsoring this video! Disassemble, decompile & debug with IDA Pro, the state of the art binary code analysis tool. Code HAMMOND50 takes 50% off any IDA Pro product and HAMMOND30 takes 30% off any IDA Pro training π jh.live/hex-rays
02.10.2025 13:01 β π 2 π 0 π¬ 0 π 0
Golang reverse engineering walkthrough! A challenge we solve with three different approaches: (1) static analysis with IDA, (2) dynamic analysis in a debugger and (3) patching the binary and switching to a desired code path π youtu.be/4-7zcq5-cNA
02.10.2025 13:01 β π 10 π 1 π¬ 1 π 0
A chat and demo with James Spiteri to see just how easy it is now to spin up Elastic -- and all that includes for free! We test malware, ES|QL, detections, AI triage, hunting, and everything free and easy for home labs, education, and real environments! π youtu.be/7Z2zObdhN-Q
25.09.2025 13:00 β π 6 π 0 π¬ 1 π 0
And a hat-tip to @ rd_pentester for his original blog writeup covering ServiceUI.exe!
23.09.2025 13:01 β π 3 π 0 π¬ 0 π 0
Try AttackForge - Pentest Management and Reporting
Leverage features that help you manage and deliver your pentesting better
Huge thanks to AttackForge for sponsoring this video! Manage your penetration testing programs and deliver large-scale pentesting services with AttackForge -- get started with a self-service free trial: jh.live/attackforge
23.09.2025 13:01 β π 2 π 0 π¬ 1 π 0
Video showcase of the ServiceUI.exe living-off-the-land (sorta) binary: elevation to NT AUTHORITY\SYSTEM, proxied execution that may evade detections AND a viewer-submitted PowerShell wrapper for spawning cmd.exe as Trusted Installer with all privileges π youtu.be/BsEwsKQJtk8
23.09.2025 13:01 β π 7 π 0 π¬ 2 π 0
Products
Industry leading password security & end user authentication products - natively integrated with AD.
And a huge thanks to Specops Software for sponsoring this video and their continued support of the channel! Protect your organization with stronger passwords, and continuously scan and block over FOUR BILLION breached passwords with SpecOps Software! jh.live/specops-yt
11.09.2025 13:11 β π 4 π 0 π¬ 0 π 0
Clever & cutesy malware infection chain, starting with a typosquat domain, "ClickFix-like" setup but actually not ClickFix -- search-ms: handler to attacker network share, fake PDF lure to download and run an MSI-- ultimately another commodity stealer tho. youtu.be/EZ6TEjx7JLw
11.09.2025 13:11 β π 10 π 0 π¬ 1 π 0
Drata + John Hammond
Automate Evidence Collection. Collect documentation from your tech stack. 190+ integrations and an open API.
Big thanks to Drata for being the sponsor of this video and their continued support of the channel! Bring Governance, Risk and Compliance (GRC) work into the modern age with Drata: jh.live/drata
04.09.2025 13:00 β π 0 π 0 π¬ 0 π 0
Top 5 Ways You Get Hacked -- casual video without a demo, but some fun looking through a recent writeup (or low-key rant, they say) from @SecurityAura "Ransomware in SMBs: Top 5 Missing or Incomplete Controls That Could Help Prevent or Cripple Attackers" youtu.be/AG3DYX4_EE4
04.09.2025 13:00 β π 8 π 1 π¬ 1 π 0
Very late on getting this video out the door, but a teeny weeny showcase of the recent Docker for Desktop on Windows & MacOS container escape, CVE-2025-9074 -- proof of concept was included so a simple demo of arbitrary file write & file read on the host: youtu.be/dTqxNc1MVLE
03.09.2025 13:05 β π 5 π 4 π¬ 0 π 0
See Threats Before They See You
Flare continuously monitors the dark web and criminal underground to help you detect and respond to cybersecurity risks faster.
Big thanks to Flare for sponsoring this video and their continued support of the channel! Track data on the dark web and manage threat intelligence for your exposed attack surface with Flare -- try a free trial and see what info is out there: jh.live/flare
28.08.2025 14:30 β π 1 π 0 π¬ 0 π 0
The fake EUROPOL / Qilin ransomware gang notice that flew around a few weeks ago was a funny story. I yapped about it in a video and briefly peeked into some Telegram channels to see cybercrime kiddos dropping LOLs and LMAOs on their counterintel op: youtu.be/gJ7gjZr6qIk
28.08.2025 14:30 β π 2 π 0 π¬ 1 π 0
Pay Forward What You Can - Antisyphon Training
Hands-On Cybersecurity Training Starting at $0.00 β Join us Live or On-Demand! Includes Cyber Range Access, Certificate of Completion, and six months access to class recordings!
Big thanks to Antisyphon Training and Black Hills information Security for sponsoring this video and their continued support of the channel! Jump into "Pay Forward What You Can" training at Antisyphon Training, at whatever cost makes sense for you! jh.live/pfwyc
26.08.2025 13:00 β π 3 π 0 π¬ 0 π 0
Video showcase of the recent WinRAR 0-day, CVE-2025-8088, uncovered by ESET after threat actor RomCom exploited it in the wild leveraging alternate data streams & path traversal on Windows -- we examine the uncovered RAR file and a proof-of-concept demo! youtu.be/rkMNOC8fhUQ
26.08.2025 13:00 β π 11 π 3 π¬ 1 π 0
HTTP/1.1 Must Die
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
Big thanks to @PortSwigger for sponsoring this video -- you can read all the details about his insane research here jh.live/http1mustdie and see what else him and PortSwigger and the whole @Burpsuite team are up to: jh.live/portswigger :)
25.08.2025 13:01 β π 4 π 0 π¬ 0 π 0
I FINALLY got a chance to chat with James Kettle @albinowax and hear about his latest research, with a cool caption "HTTP/1.1 Must Die" π Mind-blowing work including desync attacks and critical vulnerabilities affecting websites & CDNs... and a demo! youtu.be/n3Bw8CASnHE
25.08.2025 13:01 β π 10 π 1 π¬ 1 π 0
the recording of my talk on the Black Hat show floor is up on yout00b :) youtu.be/whhOYRWd_rs
22.08.2025 13:15 β π 10 π 1 π¬ 0 π 0
Download AnyDesk for Free
Download AnyDesk for free and access, control and administrate all your devices when working remotely.
Big thanks to @AnyDesk for sponsoring this video and their continued support of the channel! Join the fight against scammers alongside AnyDesk, with fast remote desktop software and access from anywhere! jh.live/anydesk
21.08.2025 13:00 β π 3 π 0 π¬ 0 π 0
An alternative to Shift+F10 to open an administrative command prompt during the Windows initial setup and Out-of-Box-Experience (OOBE) -- video showcase of @_bka_ 's newfound trick to revive a simple method for backdoors and unintended access: youtu.be/idogu3Y6ia8
21.08.2025 13:00 β π 8 π 0 π¬ 1 π 0
See Threats Before They See You
Flare continuously monitors the dark web and criminal underground to help you detect and respond to cybersecurity risks faster.
Big thanks to @FlareSystems for sponsoring this video and their continued support of the channel! Track data on the dark web and manage threat intelligence for your exposed attack surface with Flare -- try a free trial and see what info is out there: jh.live/flare
20.08.2025 13:02 β π 1 π 0 π¬ 0 π 0
The γ Japanese hiragana character: recently used in Booking[.]com phishing campaigns as a "Punycode" Unicode lookalike symbol for forward slashes in URL links! Homoglyph attack that makes us curious what, if any, other lookalike characters do the same: youtu.be/nxVr4ERhrPQ
20.08.2025 13:02 β π 12 π 4 π¬ 1 π 0
BloodHound Feature Comparisons - SpecterOps
BloodHound 8.0 update adds BloodHound OpenGraph β expanding attack path visibility beyond AD and Entra ID.Β Learn More
Big thanks to our channel partners @SpecterOps for their support with this video π Map anything with the free and open-source BloodHound Community Edition, or defend your environment with Bloodhound Enterprise! jh.live/bloodhound
19.08.2025 13:03 β π 1 π 0 π¬ 1 π 0
The new Bloodhound version has some genuinely crazy cool new features -- OpenGraph really blows the doors off the potential for Bloodhound to not just map attack paths within Microsoft Active Directory or Entra ID tenants, but now... ANYTHING π€© youtu.be/kVOjXGbm_Ro
19.08.2025 13:03 β π 8 π 2 π¬ 1 π 0
Home - Cape
Premium, nationwide cell service for $99/month, with no hidden costs. Try your first month for justΒ $30.
Big thanks to @CapeCellular for sponsoring this video! Protect yourself with private cell service built with security and privacy at its core. You can use my code "HAMMOND33" to get 33% off your first 6 months with Cape: jh.live/cape
18.08.2025 13:02 β π 1 π 0 π¬ 0 π 0
I have horrible news. YouTube thumbnails with my stupid, dumb face are back.
Minecraft malware inside a ChatTrigger mod that makes (hilariously) almost no effort whatsoever to obfuscate or hide its functionality: youtu.be/oQvKoJAbm98
18.08.2025 13:01 β π 6 π 0 π¬ 1 π 0
Cybersecurity, Battletech, and Sci-Fi.
Microsoft MVP (Security), Identity Architect, .NET Developer and Windows Platform Specialist. Founder of @lithnet_io.
Mastodon: @ryannewington@infosec.exchange
Twitter: @RyanLNewington
Senior Security Researcher (DART) at Microsoft. Opinions are my own. #MSIncidentResponse #DART #Microsoft365 #EntraID #DefenderXDR #Sentinel
Cybersecurity Aficionado, Privacy Advocate, Founder and Co-Host of the Shared Security Podcast @sharedsecurity.bsky.social
Curator of @retrorelics.store
Also: Sober π, Metalcore π€, Cats π, Retro video games, mods, vintage consoles and repair.
Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) πΊπΈ A mostly unserious person. @therealc3rul34n.bsky.social is bae π₯°
security architect / co-founder @digitaldefenseinstitute.com / co-founder Recon InfoSec
β₯β₯β₯ == @eric.zip, nerdery, rainbows, sweatpants
she/her | mama of 3 | π€ππΏππ
unicorns.lol
https://short-stack.net
whitneychampion.com/portfolio
π₯ Hope Dealer | π Table Flipper | π¨ Artist
π Tribe of Hackers, US Navy, NSA, DIA, Builder
π Hacker | π£οΈ InfoSec, Coding, GenAI
π‘ Simplifying tech, mentoring, building communities
π My new books >> Spot the Wolf & Hacker Inc.
π Legacy > clout
Team Lead Kovert AS, previously Red Team TrustedSec, terrible creator of InfoSec content πΉOpinions are my own and not the views of my employer.
sr detection engineer @ huntress β’ malware enjoyer β’ macOS security
https://alden.io
I cover digital threats for NBC News. Tip me! @kevincollier.01 on signal, kevin.collier@nbcuni.com. NYC, from West Virginia.
I'm here for Dad Rock, Cybersecurity, and Soccer. Not necessarily in that order.
Job: VP of Product Marketing at Halcyon
Location: Greenville, SC
(he/him) Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
software engineer @ fintech- content creator @ http://links.ali.dev - threatwire host @hak5 - @breakingthepod - nyc - ex @miteecs - jewish
Researcher and PhD student. Malware, memory forensics, reverse engineering, macOS, ICS/OT. Music nerd and concert junkie. Personal account and opinions my own.
rmettig.github.io/about
Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
π Trusted Threat Detection & Incident Response solutions. Experience the difference with our unmatched capabilities. #SIEM #APISecurity #LogManagement #InfoSec
The best asset for Tech Creators π»
Video Editor + Thumbnails π₯
Post-Production Professional ππ
Building β‘οΈ @prolificvisuals.bsky.social
I nudge people to care about privacy and security. CPO/DPO. Privacy/infosec lawyer. Hacker. Fighting for privacy, digital civil liberties & the users. Ex @EA @FTC |my views are my own. I used to post on Twitter at @wbm312.