Sign in

Max Andreacchi

@atomicchonk.bsky.social
231 followers 358 following 40 posts

Head of AI Research @ zero-lab.ai Corgi dad 🐶 Cat servant 🐱 Tattoo collector 🖼️ Runner 🏃🏻

PostsRepliesMedia
Max Andreacchi @atomicchonk.bsky.social · 25/07/2026
This week zero-lab.ai came out of stealth, and I have the absolute pleasure of sharing my vulnerability disclosure to @anthropic.com via the @hacker0x01.bsky.social platform. Many thanks to them for their quick validation. Check out the vulnerability report here: zero-lab.ai/article?slug...
zero-lab.ai
Shared Origin, Shared Storage: A Cross-Account Data Leak in Claude for Android
During a review of Claude's Artifact sandbox across client platforms, Zero-Lab identified a cross-account data persistence vulnerability in the Claude Android app. The Android client configured its…
010
Reposted by Max Andreacchi
SpecterOps @specterops.io · 05/09/2025
Spoiler alert: Your AI safety measures might have a blind spot. 👀 When attackers use conversation context to bypass LLM safeguards, single-prompt evals just don't cut it anymore. Dive into @atomicchonk.bsky.social's latest blog on multi-prompt attack detection. ghst.ly/47qJhzn
ghst.ly
This One Weird Trick: Multi-Prompt LLM Jailbreaks (Safeguards Hate It!) - SpecterOps
Using multiple prompts within the context of a conversation with an LLM can lead to safeguard bypasses. Learn about safeguards evaluations at scale.
061
Reposted by Max Andreacchi
SpecterOps @specterops.io · 20/06/2025
Potato exploits have been a cornerstone of local priv esc on Windows for years, but how & why do the inner starchy workings of the potatoes function? Join @atomicchonk.bsky.social next week to understand Windows access tokens & their use in the Windows environment. ghst.ly/june-web-bsky
051
Reposted by Max Andreacchi
XPN @xpnsec.com · 03/06/2025
New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...
specterops.io
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
051
Reposted by Max Andreacchi
SpecterOps @specterops.io · 29/05/2025
It's potato harvest season! 🥔 Join our upcoming webinar w/ @atomicchonk.bsky.social as he breaks down the starchy workings of potato exploits — from Windows access tokens to technical walkthroughs of Rotten, Juicy, and Rogue potatoes. Register at ghst.ly/june-web-bsky
051
Reposted by Max Andreacchi
Jim Sykora @jimsycurity.adminsdholder.com · 27/05/2025
Just wrapped up a blog post on understanding BadSuccesor from a DACL abuse aspect and mitigating it from a DACL abuse perspective. Also added some PowerShell on my GitHub to create and remove the mitigations.
1142
Reposted by Max Andreacchi
SpecterOps @specterops.io · 27/05/2025
BadSuccessor is a new AD attack primitive that abuses dMSAs, allowing an attacker who can modify or create a dMSA to escalate privileges and take over the forest. Check out @jimsycurity.adminsdholder.com's latest blog post to understand how you can mitigate risk. ghst.ly/4kXTLd9
ghst.ly
Understanding & Mitigating BadSuccessor - SpecterOps
Understanding the impact of the BadSuccessor AD attack primitive and mitigating the abuse via targeted Deny ACEs on Organizational Units.
0169
Max Andreacchi @atomicchonk.bsky.social · 24/05/2025
If you haven’t read the BadSuccessor blog post, woo boy: www.akamai.com/blog/securit...
akamai.com
020
Max Andreacchi @atomicchonk.bsky.social · 22/05/2025
I’m convinced most learning happens when you’re doing what I call “smacking into something;” failing repeatedly, figuring out why it failed, and proceeding to the next step where you rinse and repeat until you achieve your ultimate objective. TIL: docker and podman dependencies collide.
media.tenor.com
a rainbow and a star with the words " make you know " on it
ALT: a rainbow and a star with the words " make you know " on it
110
Max Andreacchi @atomicchonk.bsky.social · 20/05/2025
Beyond hyped to be presenting with @anam0x.bsky.social and the rest of my team at Arsenal at BHUSA 2025! app.ingo.me/q/0x9xn
app.ingo.me
Black Hat USA 2025
060
Reposted by Max Andreacchi
Tony Lambert @forensicitguy.bsky.social · 19/05/2025
Do you miss "@cobaltstrikebot"? If so, here's a blog post showing how you can pull Cobalt Strike SpawnTo and watermark info with @shodanhq.bsky.social and some PowerShell: forensicitguy.github.io/squeezing-co...
forensicitguy.github.io
Squeezing Cobalt Strike Threat Intelligence from Shodan
One of my favorite Twitter accounts from the last several years was @cobaltstrikebot, mainly because it was an awesome source of threat intelligence for Cobalt Strike beacons in the wild. The account ...
0116
Max Andreacchi @atomicchonk.bsky.social · 18/05/2025
It was an absolute pleasure to speak at @cackalackycon.bsky.social today and share my love of potatoes. Thank you to @specterops.io for fueling me to always go a layer deeper in learning and motivating me to chase my passions 🥔
172
Reposted by Max Andreacchi
cackalackycon @cackalackycon.bsky.social · 17/05/2025
What do potatoes have to do with privilege escalation on Windows? Come find out at Max Andreacchi’s session, “Tater Tokens: Introduction to Windows Access Tokens and Their Role in PrivEsc” on May 18th!
021
Reposted by Max Andreacchi
SpecterOps @specterops.io · 12/05/2025
Why do potato exploits work & how can we stop them? Join @atomicchonk.bsky.social at @cackalackycon.bsky.social this weekend for a walkthrough of Windows access token manipulation and get the answer. ghst.ly/4jzjlnI
052
Max Andreacchi @atomicchonk.bsky.social · 03/05/2025
Always enjoy the views in Seattle! Spent excellent quality time with teammates and received amazing training. Now for a weekend of running and resting back home before new travels next week ✈️
010
Reposted by Max Andreacchi
SpecterOps @specterops.io · 28/04/2025
Don't let threat actors mash your Windows security! @atomicchonk.bsky.social’s @cackalackycon.bsky.social talk breaks down potato exploits from token mechanics to defensive implementations. Learn more ➡️ ghst.ly/4jzjlnI
042
Reposted by Max Andreacchi
North Carolina Courage @nccourage.com · 27/04/2025
NC BABYYY 💙
Fulltime Win Graphic: NC Courage 3-2 KC Current.
16716
Max Andreacchi @atomicchonk.bsky.social · 24/04/2025
I’ve had to beat stubbornness out of my training. When I ran 10+ yrs ago I’d just hard-head my way forward but wind up injured. This time I’m focused on the goals ahead; nagging aches mean a rest day tomorrow so I can live to run later this week and keep this train moving to Oct (and beyond)
030
Reposted by Max Andreacchi
SpecterOps @specterops.io · 18/04/2025
Understanding Windows access tokens could be your best defense. At @cackalackycon.bsky.social, @atomicchonk.bsky.social will be peeling back the layers on potato exploits that threat actors use for privilege escalation. Check out the schedule to learn more ➡️ ghst.ly/4jzjlnI
063
Reposted by Max Andreacchi
Dr Nestori Syynimaa @drazuread.com · 18/04/2025
Just pushed a new versions for #AADInternals and AADInternals-Endpoint modules! Some bug fixes plus support for: 1️⃣ Microsoft Authentication Library (MSAL) 2️⃣ Token Protection 3️⃣ Continuous Access Evaluation (CAE)
1155
Reposted by Max Andreacchi
Catalin Cimpanu @campuscodi.risky.biz · 17/04/2025
The Ketman Project has published a list of names and GitHub profiles they believe may be North Korean rogue IT workers posing as open-source developers and freelancers, and seeking employment at Western software companies www.ketman.org/dprk-it-work...
ketman.org
DPRK IT Workers in Open Source and Freelance Platforms
A cluster of actors discovered in onlyDust.com freelancer platform and beyond
086
Max Andreacchi @atomicchonk.bsky.social · 16/04/2025
Initial stab at using Chris Hayuk's mcp-cli tool to pair roadrecon_mcp_server with a locally-hosted model (in this case, mistral-small3.1). Note that running this query took over 300s so YMMV depending on several factors. Will update GH this week with instructions on replicating this.
020
Reposted by Max Andreacchi
SpecterOps @specterops.io · 09/04/2025
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
12720
Max Andreacchi @atomicchonk.bsky.social · 08/04/2025
Yesterday I broke 100 miles of running in 2025 on the 97th day of the year 🎉 Using this weekend’s 5K as the long run in my training plan on the road to a 10K in June 🏃🏻‍♂️ #runsky
150
Max Andreacchi @atomicchonk.bsky.social · 07/04/2025
Everybody’s using AI assistants and tools these days, but do most of us understand how our text-based input is being interpreted and processed? Check out my latest blog post for a basic intro to text interpretation by AI assistants. www.corgi-Corp.com/post/tokeniz...
corgi-corp.com
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
051
Max Andreacchi @atomicchonk.bsky.social · 30/03/2025
While I wait on hardware for local model hosting, I modified roadrecon_mcp_server to ingest a "caps.html" file instead of inferring the tenant's CAPs based on GUI data. By default it'll look in C:\Temp for your file, but this can be specified as shown in the video. #ai #llm #mcp #infosec #microsoft
000
Max Andreacchi @atomicchonk.bsky.social · 29/03/2025
Procrastinated long enough but the GPU upgrade happens next week. R&D goals finally forced it, so we’ll be grinding more MCP dev shortly. Goal is to get roadrecon_mcp_server FULLY local, reducing data privacy concerns on Azure data collection and where it resides. Local LLMs here I come.
020
Max Andreacchi @atomicchonk.bsky.social · 29/03/2025
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This #MCP takes the web GUI output from the awesome ROADtools by @dirkjanm.io and offers tools to Claude (or your #AI agent of choice) to interact with the data: github.com/atomicchonk/...
github.com
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
2115
Max Andreacchi @atomicchonk.bsky.social · 28/03/2025
You can be anything you want, why not NT AUTHORITY\SYSTEM? Learn how you can be your best system-level self at my talk, "Tater Tokens: Intro to Windows Access Tokens and Their Role in PrivEsc" at @cackalackycon.bsky.social May 16-18. Join us for nerdy chatter, Malort, and general #hacking fun.
041
Max Andreacchi @atomicchonk.bsky.social · 28/03/2025
Late night #AI 🐰 🕳️ : #MCPs and Data Anonymization 🧵 ⬇️
100
Max Andreacchi @atomicchonk.bsky.social · 21/03/2025
TIL that Protected Users Security Group membership does not stop someone from using Kerberos with AES256 encryption type to authenticate as said user (it only prevents DES and RC4 encryption types in pre-auth). learn.microsoft.com/en-us/window...
learn.microsoft.com
Protected Users Security Group
Learn about the Active Directory security group Protected Users feature, and how it works.
010
Reposted by Max Andreacchi
Keith @keithdunn.bsky.social · 18/03/2025
After multiple failed attempts, the conch was blown at 10:37. The 2025 Barkley Marathons begins in one hour. #BM100.
531409248
Max Andreacchi @atomicchonk.bsky.social · 17/03/2025
About a month out from my 4 miler at UNC, any amount y’all could toss at this fundraising campaign for the AKC CHF would be super appreciated 🙏🏼 #running #runsky event.racereach.com/tar-heel-10-...
event.racereach.com
2025 Tar Heel 10 Miler and 4 Miler | Chapel Hill, NC | 04/19/2025
120
Reposted by Max Andreacchi
cackalackycon @cackalackycon.bsky.social · 17/03/2025
CackalackyCon has a 101 page to learn all about our conference and what to expect. cackalackycon.org/ck...
032
Max Andreacchi @atomicchonk.bsky.social · 12/03/2025
See y’all at @cackalackycon.bsky.social in 65 days! Time to tango with taters and tokens! #redteam #hacking #infosec
051
Reposted by Max Andreacchi
Li Chen @exocomics.com · 11/03/2025
walk time 🤖
82101221
Reposted by Max Andreacchi
Ann Bartow @annbartow.bsky.social · 10/03/2025
Billboard that says have a super Mar 10. The background is from the Mario Brothers game.
112089
Max Andreacchi @atomicchonk.bsky.social · 07/03/2025
Just watched @secureworks.bsky.social Yuya Chudo’s talk from BH 2024 on bypassing Entra’s CAPs when it comes to device auth/restrictions. Great insight to understanding how MSFT handles device auth and how it’s abusable. Always love to see a demo go right at hacker camp 🎉 youtu.be/JItnI6b9DII?...
youtu.be
Bypassing Entra ID Conditional Access Like APT: A Deep Dive Into Device Authentication Mechanisms
YouTube video by Black Hat
000
Reposted by Max Andreacchi
SpecterOps @specterops.io · 05/03/2025
BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments. ghst.ly/seriesb #IdentitySecurity #CyberSecurity (1/6)
1159
Max Andreacchi @atomicchonk.bsky.social · 20/02/2025
Would SUPER appreciate anyone that wants to support the charity cause of my upcoming race in April: the AKC Canine Health Foundation! event.racereach.com/tar-heel-10-... I know I want these two around for as long as possible and supporting new treatments and preventive solutions enables that ❤️
110
Reposted by Max Andreacchi
SpecterOps @specterops.io · 05/02/2025
Introducing Forge 🔥 – the first “Command Augmentation” container for Mythic! Check out @its-a-feature.bsky.social's latest blog post to learn how this new add-on offers a more standardized way of executing BOFs and .NET assemblies. ghst.ly/416iKnu
ghst.ly
Forging a Better Operator Quality of Life
A new Mythic add-on for Windows Agents
0105
Reposted by Max Andreacchi
SpecterOps @specterops.io · 16/01/2025
Curious about what it's like working as a consultant and red teamer here at SpecterOps? Check out this blog post from @subat0mik.bsky.social sharing his perspective: ghst.ly/3AEEKe5
ghst.ly
Life at SpecterOps: The Red Team Dream
Come work with us!
042
Max Andreacchi @atomicchonk.bsky.social · 16/01/2025
Winnie, my corgi, wrote a blog post on LAPS while she navigated “Timelapse” on HTB 👀 www.corgi-corp.com/post/running...
corgi-corp.com
Running Laps on LAPS feat. HTB Timelapse
Winning the race on DACL abuse and LAPS through a HTB Timelapse walkthrough
030
Max Andreacchi @atomicchonk.bsky.social · 24/12/2024
Both interested in your cookies for different reasons 🍪 Happy Christmas Eve from Santa and the Grinch #hackthebox
Man wearing a Christmas themed sweatshirt and Santa hat carrying a corgi in a backpack
030