Sign in

Nicolas Grégoire

@agarri.fr
4.5K followers 619 following 1K posts

Web hacker 😈 Burp Suite Pro trainer 👨‍🏫 Maintainer of @mastering-burp.agarri.fr 🛠️

PostsRepliesMedia
Nicolas Grégoire @agarri.fr · 27/05/2026
I'll give a single public on-site Burp Suite Pro training session this year, and it will be in RomHack 🇮🇹 (registration link in replies) And if you're not sure this course would fit you, just give a look at this recent feedback
Screenshot from X: "I dont post that much, but I do when I feel like its worth it - I have to say having taken the Burp suite Pro training by @Agarri_FR I was totally blown away. I have used burp for over 20 years and have learnt so much that will immediately help me, totally recommend the course!"
134
Nicolas Grégoire @agarri.fr · 10/02/2026
Another highly satisfied trainee 😎 👨‍🏫 If you want to take the online version of my Burp Suite course, there are two opportunities really soon (March in French, April in English) hackademy.agarri.fr/sessions And if you want to indulge your company a private session (like this company did), ping me!
Last week, I had the opportunity to attend the 4-day Mastering Burp Suite Pro training by 🛠️ Nicolas Gregoire, and it exceeded my expectations by far.

This wasn’t just another slide-driven course. Nicolas took the time to answer every question in depth and provided plenty of hands-on labs, allowing us to immediately apply what had just been explained.

Even though I’ve been working with Burp for nearly five years, I still picked up a surprising number of new techniques and practical tricks, including ways to streamline otherwise time-consuming workflows such as managing CSRF tokens both with and without session handling rules.

What I especially appreciated were the little side explorations (driven by our requests) into methodologies for leveraging features and extensions to remain stealthy or bypass WAFs. This is something that’s particularly relevant (and often underestimated) when exploiting external or internal web applications during advanced Red Team engagements.

I’m genuinely looking forward to applying this newly gained knowledge in upcoming projects, and I can wholeheartedly recommend this training to any (web) pentester who wants to level up their Burp skills.

Big thanks to Nicolas for an excellent and highly practical course!
041
Nicolas Grégoire @agarri.fr · 06/12/2025
Printed version of Paged Out #7, collected during GreHack 2025 🤩
Printed version of Paged Out #7, collected during GreHack 2025
061
Nicolas Grégoire @agarri.fr · 19/11/2025
A nice sunset
0101
Nicolas Grégoire @agarri.fr · 09/11/2025
Capture (partielle) d’un article du Monde consécutif à la condamnation de Florent Curtet
000
Nicolas Grégoire @agarri.fr · 13/10/2025
Gecko Security stole some vulnerabilities published, among others, by Fuzzing Labs 😱 They also asked for CVE IDs 🤡 Check if your research is impacted too! www.notion.so/fuzzinglabs/...
070
Nicolas Grégoire @agarri.fr · 26/09/2025
#FrenchPolitics
A mugshot of former president Sarkozy
171
Nicolas Grégoire @agarri.fr · 10/09/2025
Apparently I’m not the only iPhone user in love with small phones Dimensions: 135 x 65 mm for the 13 Mini vs 150 x 72 mm for the 17
Searching for "iphone mini" after yesterday’s keynote reveals that some users really like small iPhones like the 13 Mini
121
Nicolas Grégoire @agarri.fr · 31/08/2025
I was lucky enough to have beautiful sunsets every day of my stay 🤩
Another beautiful sunset over the Spree
120
Nicolas Grégoire @agarri.fr · 29/08/2025
Hi from Berlin 🇩🇪
Sunset on the Spree river
160
Nicolas Grégoire @agarri.fr · 23/08/2025
20 yo printed copy of @phrack.org #63 👴
A printed copy of Phrack 63, released at the dutch hacker camp WTH 2005
0192
Nicolas Grégoire @agarri.fr · 23/08/2025
Old school Wifi hacker 😎
Old PCMIA cards I used for Wifi hacking decades ago: Linksys WPC11 v3 and 3COM 3CRPAG175B
2111
Nicolas Grégoire @agarri.fr · 18/08/2025
When I was fuzzing Microsoft Office circa 2015, I printed 10% of ECMA-376. That was a great investment, as I found more than a dozen vulns #OldMemories #AtticCleaning
The 16 first chapters of ECMA-376 + the annex L. A total of ~ 500 pages
060
Nicolas Grégoire @agarri.fr · 17/08/2025
How to "cheese" CTF challenges, by @pilvar.bsky.social m.youtube.com/watch?v=Sm4G...
From the Urban Dictionary : "cheese" is a term coined by RTS gamers when a player uses non ordinary measures, often considered cheap tactics, to win the game early.
061
Nicolas Grégoire @agarri.fr · 16/08/2025
The talk @parsiya.bsky.social gave at Defcon should be a required read for all users of Burp Suite Bonus point: it contains a meme I created 😊 github.com/parsiya/Pres...
A meme I created. It shows Calvin (from Calvin & Hobbes) seated at a table with a sign saying "Chaining two instances of Burp Suite is such an underrated technique. Change my mind"
185
Nicolas Grégoire @agarri.fr · 14/08/2025
Got postcards from the Chaos Post Office too! 📨
A few postcards edited by the Chaos Post Office
021
Nicolas Grégoire @agarri.fr · 14/08/2025
Tons of swag have been acquired during @why2025.bsky.social 🎁
A collection of swag: a harpon of our village, the WHY and Phrack glasses, a Cyber Sayan coin, a badge and some stickers Three printed editions of the Phrack magazine
141
Nicolas Grégoire @agarri.fr · 11/08/2025
Day 4 of @why2025.bsky.social Junk food 🍞🍬🍟 Fun workshops 🤓
Folding balloons workshop Breakfast itemsThe official map + my own certificate of awesomeness Silent disco (which is a techno party) 🪩
021
Nicolas Grégoire @agarri.fr · 11/08/2025
Sunset on Day 3 of @why2025.bsky.social ☀️
Sunset on Day 3 of WHY 2025Sunset on Day 3 of WHY 2025
020
Nicolas Grégoire @agarri.fr · 10/08/2025
Day 2 of @why2025.bsky.social ended with toasted marshmallows 🔥
Toasting marshmallows by the bonfire Toasting marshmallows by the bonfire
042
Nicolas Grégoire @agarri.fr · 09/08/2025
Now we are Day 2 ⛺️🔥 Opening talk in progress @why2025.bsky.social
Audience of the opening ceremony in the largest room, Andromeda
031
Nicolas Grégoire @agarri.fr · 09/08/2025
Day 1 of @why2025.bsky.social is over 🪩
Light show during the night
041
Nicolas Grégoire @agarri.fr · 08/08/2025
Welcome to DAY 1 🏁 @why2025.bsky.social
Morning at the Dutch camp
051
Nicolas Grégoire @agarri.fr · 05/08/2025
Here’s Mobelhaus delivering tables and chairs to our village 👀
Screenshot of the WHY2025 map. A vehicle named MobelhausGator is parked next to the village RandomOrange
010
Nicolas Grégoire @agarri.fr · 04/08/2025
La logique voudrait que l’on tape d’abord sur les employeurs… 🇫🇷💸
La fraude à l’URSAAF représente 53% du montant total
020
Nicolas Grégoire @agarri.fr · 29/07/2025
@jrn.bsky.social Are you coming to @why2025.bsky.social? I still have your number in my DECT
A DECT phone I use during Dutch hacker camps. It shows a phonebook entry for @jrn
250
Nicolas Grégoire @agarri.fr · 28/07/2025
Getting ready for @why2025.bsky.social ⌛️👨‍🍳
Custom napkins with the RandomOrange et Agarri logos. The text reads "Bon appétit !"
060
Nicolas Grégoire @agarri.fr · 25/07/2025
The @why2025.bsky.social badge looks incredible!! 🤩 why2025.org/post/697
Stock badge, including a real keyboardSame badge, but with a different cover and a LoRa antenna
180
Nicolas Grégoire @agarri.fr · 11/07/2025
The Dutch hacker camp @why2025.bsky.social is officially sold out 🥳 Now I’m impatient to meet the 3,750 other nerds and hackers ⌛️ See you in Geestmerambacht ⛺️
Public dashboard showing a plateau of tickets sales after 3,751
160
Nicolas Grégoire @agarri.fr · 25/06/2025
TIL about `fold`, a simple CLI utility which splits a large string in chunks of a specific size ✂️ Perfect for the AES-ECB challenge I'm working on! 😈
Screenshot of the man page for fold
110
Nicolas Grégoire @agarri.fr · 21/06/2025
A company took my training for the second time (a few years after the first one), trainees still love it 💪 😎 Look at the alt-text for an English translation 🇫🇷 🇬🇧 Did I tell you I'll give this training during Rom'Hack (late September, Roma)? And a few seats are still available...
Second training session with Nicolas and we're still learning a lot. I'd like to emphasize once again the quality of the training, which is one of the best available. The time between theory and practice is very well managed and you never see the week go by. I particularly liked the pedagogical approach, and the combination of technical and business objectives to fine-tune attacks. At the end of the session, you realize that you were using barely 20% of the functionalities offered by the Burp tool.
162
Nicolas Grégoire @agarri.fr · 18/06/2025
A pretty sunset… 📷
Sunset shot from a hill next to my home
161
Nicolas Grégoire @agarri.fr · 05/06/2025
OMG, that's wrong on so many levels... 🤦 (note: Aylo is the owner of Pornhub) www.aylo.com/newsroom/ayl...
A press release from Aylo (owner of Pornhub) saying that "All it requires is that the government enforce regulations on three companies – Apple, Google and Microsoft – the three operating system manufacturers requiring age verification at the device level prior to accessing adult content"
110
Nicolas Grégoire @agarri.fr · 03/06/2025
Pareil !
Le fameux lapin à trois yeux, du même auteur que les célèbres enfants à neuf doigts
030
Nicolas Grégoire @agarri.fr · 03/06/2025
Fait exprès ? J’aimerais bien vous croire, mais là j’ai vraiment du mal
Le lapin présent sur la couverture. Il a trois yeux
110
Nicolas Grégoire @agarri.fr · 13/05/2025
Another example (thx @swapgs.infosec.exchange.ap.brid.gy for the link), this time involving Sonar Source and Postman www.sonarsource.com/blog/scripti...
An extract of the timeline:
- 2024-03-19: We report the issues to Insomnia and Postman via email
- 2024-03-19: The Postman team asks us to use their bug bounty platform instead
- 2024-03-21: We decline Postman's request due to conflict with our disclosure policy
034
Nicolas Grégoire @agarri.fr · 11/05/2025
The WatchTowr advisories are really fun to read 🤭 labs.watchtowr.com/by-executive...
A screenshot of the advisory. The text: says:

We get chastised for not following someone else's random definition of responsible disclosure, but where is the accountability for vendors who update a text file every time their solution gets popped?
080
Nicolas Grégoire @agarri.fr · 11/05/2025
After last week example (ERNW), here’s another infosec company (WatchTowr) which refused to abide by the vendor’s vulnerability disclosure terms labs.watchtowr.com/sysowned-you...
20 December 2024: First XXE vulnerability report sent to SysAid.

22 December 2024: SysAid responds, stating they are unable to reproduce the XXE and highlights that they have their own vulnerability disclosure terms & conditions they’d like to somehow commit us to.

22 December 2024: watchTowr checks with counsel to ensure that it’s still not possible to arbitrarily bind people to random contracts without agreement - counsel confirms that the world has not changed.
5158
Nicolas Grégoire @agarri.fr · 09/05/2025
A drawing with two characters 

Character A: You’ve changed 
Character B: We are supposed to
010
Nicolas Grégoire @agarri.fr · 09/05/2025
I like this kind of visualization
Tool reqvis displaying some web traffic https://github.com/ibudiallo/reqvis
210
Nicolas Grégoire @agarri.fr · 10/04/2025
Today’s mood…
Lac d’Esparron, France
191
Nicolas Grégoire @agarri.fr · 04/04/2025
Morning! 🥱
Sunrise over the Sainte Victoire (Aix en Provence 🇫🇷
0101
Nicolas Grégoire @agarri.fr · 02/04/2025
I went to all of the Dutch hacker camps since 2001 (that's not a typo) 🇳🇱 🧓 This year edition @why2025.bsky.social already sold 2,772 tickets, out of a maximum of 3,500 ⌛ Join us, it'll be a ton of fun! ⛺
Grafana dashboard showing that 2,772 tickets have already been sold
051
Nicolas Grégoire @agarri.fr · 02/04/2025
Getting feedback like this is what motivates me to work, again and again, on my Burp Suite training course. Thanks @joaxcar.bsky.social ☺️
A screenshot from Johan Carlsson's Linkedin account: "Last week, I participated in Nicolas Gregoire's course "Mastering Burp Suite Pro". I must say it was probably the single best technical course I have taken. Using Burp (one of the main tools I use daily) feels like a whole new experience. I can not recommend enough jumping on one of these sessions."
0204
Nicolas Grégoire @agarri.fr · 25/03/2025
US politics right now...
A cartoon character (depicting Jeffrey Goldberg) sits in a meeting with JD Vance, Peter Hegseth and others (cf the article "The Trump Administration Accidentally Texted Me Its War Plans")
071
Nicolas Grégoire @agarri.fr · 07/03/2025
An oldie but a goodie! www.zerodayinitiative.com/blog/2024/5/...
Screen capture with an excerpt from the article: "The resolver will first try to handle the parameter entities, and only afterwards will perform the DTD prohibition check! An exception will be thrown in the end, but it still allows you to exploit the Out-of-Band XXE and potentially exfiltrate data (using, for example, an HTTP channel)."
050
Nicolas Grégoire @agarri.fr · 22/01/2025
Sure, there's around 50 MB to download (34 MB of WASM + 16 MB of data), but you can run LibreOffice in a browser 🧙 zetaoffice.net/demo3.html
Screenshot showing LibreOffice being loaded inside a browser. The "ping" diagram is generated from network response times, and users can enter which websites to test
051
Nicolas Grégoire @agarri.fr · 28/12/2024
An easy way to get some stats regarding your (or someone’s else) Bluesky account 📊 blueskyscore.com
My stats:
- joined 604 days ago 
- has 3650 followers and 876 followings
- posted 0.93 messages per day
030
Nicolas Grégoire @agarri.fr · 25/12/2024
Happy Christmas 🎄☀️
Le lac d’Annecy - FranceLe lac d’Annecy - France
1201
Nicolas Grégoire @agarri.fr · 24/11/2024
Btw, here's my own TweetPlot...
This graph, showing my Twitter postings habits over time, was generated by https://tweetplot.streamlit.app/
020