Sign in

BC Security

@bcsecurity.bsky.social
69 followers 4 following 116 posts

Threat Emulation | Training | Red Team | Penetration Testing | Compliance

PostsRepliesMedia
BC Security @bcsecurity.bsky.social · 18/09/2026
We made the Top 10! 🎉 We're excited to announce that BC Security is a finalist in the St. Louis Startup World Cup Regional Finals! Wish us luck as we pitch #SIMAPTIC and compete for a spot in the grand finale. 🏆 #StartupWorldCup #Infosec #Cybersecurity #Tech #Startups #STL
040
BC Security @bcsecurity.bsky.social · 16/09/2026
Heading to #BlackHatEurope ? ✈️ Join the BC Security team Dec. 7 & 8 for Advanced Threat Emulation: Evasion (BH Edition), an intensive 2-day hands-on training at #BHEU. ⏳ Early bird registration is officially open. Secure your spot today! blackhat.com/europe/train...
buff.ly
Black Hat Europe 2026
Black Hat Europe 2026
000
BC Security @bcsecurity.bsky.social · 14/09/2026
Always great teaming up with @reybango! In his latest video, he and Jake dive into the DarkHaven range using Empire C2—focusing on deliberate tradecraft over quick wins. Watch the full walkthrough: www.youtube.com/watch?v=cq15...
youtube.com
Using the Empire C2 on Hack Smarter's DarkHaven Range - Part 1
I'm joined by Jake Krasnov of BC Security and co-maintainer of the Empire C2 project to do a walkthrough of Hack Smarter's DarkHaven cyber range. We focus on using a real red teaming mindset as Jake…
000
BC Security @bcsecurity.bsky.social · 10/09/2026
The goal of red teaming isn't just seeing if you can break in—it's empowering defenders. In CISA’s new advisory, A Tale of Two SOCs, their red team tested two critical orgs: one missed lateral movement entirely, while the other caught and quarantined the foothold early. (1/2)
100
BC Security @bcsecurity.bsky.social · 09/09/2026
Empire 7.0 is live! 🔥 Massive thanks to our community for the support on our biggest release yet. What’s new: • Full crypto rewrite (AES-GCM, PBKDF2) • Pivots on all agents • Multi-tab terminal & dedicated shells • 75+ new BOFs • New Starkiller UI & Agent Graph github.com/BC-SECURITY/...
github.com
GitHub - BC-SECURITY/Empire: Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. - BC-SECURITY/Empire
000
BC Security @bcsecurity.bsky.social · 08/09/2026
We're speaking at the Louisville Metro InfoSec Conference this Friday, Sept. 11th! 🎙️ Join us for: "AI in the Adversary's Toolkit: From Search Replacement to Autonomous Ops" Tickets are almost sold out! Grab your seat today: www.louisvilleinfosec.com #InfoSec #LMIC2026
000
BC Security @bcsecurity.bsky.social · 03/09/2026
The BC Security team is heading to Kentucky for the Louisville Metro InfoSec Conference next week (Sept. 11th)! Tickets are almost sold out: grab yours before they're gone! www.louisvilleinfosec.com #InfoSec #CyberSecurity #RedTeam #LMIC2026
louisvilleinfosec.com
Louisville Metro InfoSec Conference
The Louisville Metro InfoSec Conference is Louisville's longest running information and cyber security conference.
000
BC Security @bcsecurity.bsky.social · 31/08/2026
We’re teaching at the first-ever Black Hat India! 🇮🇳 Join BC Security for our new hands-on course, Attacking and Defending AI Agents—covering MITRE ATLAS kill chains, MCP exploitation, and real defenses! Early bird is live and we’re 92% sold out! Grab your spot: buff.ly/4j2Z5gA
120
BC Security @bcsecurity.bsky.social · 28/08/2026
This article outlines how a security researcher earned $500k by using AI agents to map Google's attack surface and find high-value bugs. When research like this goes public, it's a clear reminder that attackers can leverage the exact same tooling. 🔗: buff.ly/slLF6HI
brutecat.com
Hacking Google with A.I. for $500,000
What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.
010
BC Security @bcsecurity.bsky.social · 25/08/2026
We're excited to be back at #DAFITC in Montgomery, AL! Lots of powerful insights from industry leaders and great conversations around the future of cyber defense operations. #DAFITC2026 #BCSecurity #CyberSecurity
000
BC Security @bcsecurity.bsky.social · 15/08/2026
Hacker Summer Camp is always our favorite time of the year, and this Black Hat and DEF CON week was easily our best one yet. If we didn't get a chance to connect in Vegas, give us a follow here to stay up to date on our upcoming workshops and tools! #BlackHatUSA #DEFCON34 #RedTeaming #BCSecurity
000
BC Security @bcsecurity.bsky.social · 08/08/2026
DEF CON DAY 2! 🏴‍☠️ BC Security LIVE from the Demo Lab stages 😎 #EmpireC2 #DEFCON34
010
BC Security @bcsecurity.bsky.social · 07/08/2026
What a way to kick off #DEFCON34! 🏴‍☠️ Huge thanks to Hubbl3 for hosting and to everyone who showed up for our Long Live Empire red teaming workshop! 💻 We’ll be here all weekend, come say hi if you see us around! :)
010
BC Security @bcsecurity.bsky.social · 04/08/2026
Kicking off #BlackHatUSA at Mandalay Bay! 🎲✈️ Yesterday, the BC Security team debuted our new Red Team Essentials: Foundations of C2 course at Black Hat USA and it was a huge success! Thank you to everyone who joined us! You made it an awesome start to the week. #BHUSA #CyberSecurity #RedTeam
000
BC Security @bcsecurity.bsky.social · 29/07/2026
Less than a week til #BlackHat2026! 🎲 We're excited to host RED Team Essentials: Foundations of Command and Control (C2) on August 3rd! Last-minute registration is still open! Hope to see you there! 🔗: buff.ly/4APHjbZ #BlackHat #InfoSec #RedTeaming
000
BC Security @bcsecurity.bsky.social · 14/07/2026
We are excited to be teaching at DEF CON once again. We will be teaching Long Live Empire! An introduction to modern C2s. We will also go over all the new capabilities in Empire 7, releasing soon. Signups open at 12 PDT / 3 EDT & sell out fast! @defcon events.humanitix.com/fri_am_ws6_4...
events.humanitix.com
WS6 - Long Live Empire: A C2 Workshop for Modern Red Teaming
Instructed by: Jake “Hubbl3” Krasnov Level of Difficulty: Beginner
000
BC Security @bcsecurity.bsky.social · 12/05/2026
ATE: Active Directory, is at #BHUSA! Come learn all the nuances behind delegation attacks, forest trusts, certificate abuse, & more! AD is one of the largest attack surfaces in modern environments, so upgrade those skills today. Prices go up May 22nd! blackhat.com/us-26/traini...
000
BC Security @bcsecurity.bsky.social · 09/05/2026
Had a great time on the panel @HackRedCon today. Lots of interesting disucssion and the most debated one was: "Do we expect to see auditors for things like SOC 2 start accepting AI-executed security assessments in the near future?" The panel was evenly split. What are your thoughts on it?
000
BC Security @bcsecurity.bsky.social · 04/05/2026
New to offensive security & not sure where to start? Or part of the blue team looking for a broad overview of C2? Check out our new 1-day course at Black Hat, RTE: Foundations of C2. Learn the ins & outs of the core technology that attackers use. Prices go up May 22nd! blackhat.com/us-26/traini...
000
BC Security @bcsecurity.bsky.social · 24/04/2026
Back by popular demand, we will be teaching ATE: Active Directory again at #BHUSA this year! One of our most popular classes every year. Prices go up at the end of May, don't miss out! blackhat.com/us-26/traini...
000
BC Security @bcsecurity.bsky.social · 13/04/2026
BlackHat 2026 is offering 1-day courses for the first time & we are rolling out a brand new course! RTE: Introduction to Ransomware Simulation. Come learn the workflows behind ransomware & the intricacies of crypto-theft. Taught by Hubbl3 Prices go up on May 22nd! blackhat.com/us-26/traini...
blackhat.com
Black Hat USA 2026
Black Hat USA 2026
000
Reposted by BC Security
Empire @empirec2project.bsky.social · 07/04/2026
Empire v6.5 is live! - 8 new modules across BOF/C#/PS/Python - New C stager + PIC shellcode compiler for stage0 agent injection - Patchless AMSI & ETW bypasses - New Jobs tab on the agent page for managing background jobs - Python 3.14 support github.com/BC-SECURITY/...
github.com
GitHub - BC-SECURITY/Empire: Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. - BC-SECURITY/Empire
011
Reposted by BC Security
Empire @empirec2project.bsky.social · 01/04/2026
Introducing Starkiller Assistant! Our new AI-powered helper for Empire operators. It's like Clippy, but for C2. After months of R&D, early testers describe it as "confidently wrong" and "worse than no help at all." We're so proud.
021
BC Security @bcsecurity.bsky.social · 16/03/2026
According to the SBA 60% of small businesses close within 6 months of a cyber breach, yet enterprise security testing often leaves organizations priced out. That Gap shouldn't exist so we built SIMAPTIC! A fully automated internal network testing tool built on Empire.
bcsecurity.io
Introducing SIMAPTIC – An Automated Security Assessment Tool for Small Businesses and Regulatory Compliance - Offensive Security, Penetration Testing, and Training
We are introducing SIMAPTIC: an LLM-driven automated security assessment solution built on top of our open-source framework Empire, designed to make enterprise-grade security testing accessible to…
001
BC Security @bcsecurity.bsky.social · 17/02/2026
Empire 6.4 is now public! Here are just a few updates: - Added C# spawn module - Auto-install for plugin marketplace - New task display with parameters - Added "Rerun Task" to Agents and Plugins - Added customizable table headers - Added Debian 13 support
000
BC Security @bcsecurity.bsky.social · 08/01/2026
Cyber on the rise: In 2025, Taiwan experienced an average of 2.6 million daily cyberattacks on critical infrastructure, from hospitals to energy systems, up from the previous year. Many of these incidents were tied to broader military and political pressure. www.reuters.com/world/china/...
000
BC Security @bcsecurity.bsky.social · 02/01/2026
New year, new site, new tool! We’ve refreshed the BC Security website and introduced SIMAPTIC, our continuous threat-exposure and validation platform that simulates multi-stage attacks and provides teams with real signals they can act on. simaptic.ai Also, check out the new website! bcsecurity.io
000
BC Security @bcsecurity.bsky.social · 26/12/2025
Happy Holidays from all of us at BC Security! As the year winds down, we just want to say thanks to our clients, partners, and the awesome community around us. Your support means everything, and it’s what keeps us building, learning, and doing what we love. Thank you to everyone!
000
BC Security @bcsecurity.bsky.social · 12/12/2025
Empire v6.3.0 released!!!! Bringing major upgrades like Starkiller v3.2.0, mTLS support, ChaCha20-Poly1305 encryption, expanded PSExec agent options, and flexible env-based configuration — making Empire more secure and operator-friendly than ever. github.com/BC-SECURITY/...
010
Reposted by BC Security
Empire @empirec2project.bsky.social · 12/12/2025
Empire v6.3.0 is out! • mTLS agents & listeners • ChaCha20-Poly1305 encryption + DH key exchange • HTTPS host reuse across HTTP & malleable listeners • Customizable C# obfuscation via EmpireCompiler • Major dependency upgrades & stability fixes github.com/BC-SECURITY/...
github.com
GitHub - BC-SECURITY/Empire: Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. - BC-SECURITY/Empire
022
BC Security @bcsecurity.bsky.social · 01/12/2025
Cyber Monday Deal: Level Up Your Cyber Skills! One of our flagship cyber courses is going on sale, for a limited time. If you’ve been waiting to jump into hands-on, operator-level training, now’s your moment. training.bc-security.org/courses/empi...
training.bc-security.org
Empire Operations 1
Empire Operations I is an introductory hands-on course with the Empire Post Exploitation Framework. In this course, students will learn the basics of using and operating Empire while being introduced…
000
BC Security @bcsecurity.bsky.social · 20/11/2025
AI-driven cyber-espionage is now real. Anthropic reports autonomous agents running full intrusion chains with minimal human input. Defense has to move at machine speed now. Full report: www.anthropic.com/news/disrupt...
anthropic.com
Disrupting the first reported AI-orchestrated cyber espionage campaign
A report describing an a highly sophisticated AI-led cyberattack
000
BC Security @bcsecurity.bsky.social · 27/10/2025
Cybersecurity Awareness Month! Cyber Tip: Segment your administrative network and separate privileged access. Keep domain controllers, jump servers, and management systems separate from user workstations. Isolation limits lateral movement and protects privileged credentials.
000
BC Security @bcsecurity.bsky.social · 23/10/2025
Cybersecurity Awareness Month! Cyber Tip: Patch your third-party software. Attackers don’t always need zero-days, just an old plug-in or unpatched tool. Centralize patching, remove legacy apps, and stay current. Every unpatched tool is a potential entry point.
000
BC Security @bcsecurity.bsky.social · 20/10/2025
Cybersecurity Awareness Month!! Cyber Tip: Rotate service account passwords often. These high-privilege accounts are prime targets for attackers. Regular rotation limits damage and reduces risk.
000
BC Security @bcsecurity.bsky.social · 15/10/2025
Cybersecurity Awareness Month! Cyber Tip: Microsoft has officially ended support for Windows 10. Without ongoing security updates, these systems are now vulnerable to new exploits and malware. If you’re still running Windows 10, upgrade as soon as possible to stay secure and compliant.
000
BC Security @bcsecurity.bsky.social · 13/10/2025
Cybersecurity Awareness Month!!! Cyber Tip: Close what you don’t use. Unused ports and services expand your attack surface and invite scanning or exploitation. Disabling them keeps your network lean, secure, and harder to breach. #Cyberaware #CybersecurityAwarenessMonth #Cybersecurity
010
BC Security @bcsecurity.bsky.social · 10/10/2025
Cybersecurity Awareness Month! Cyber Tip: Keep an eye on outbound traffic. Attackers often use it to exfiltrate data or maintain control of compromised systems. Reviewing outbound connections helps you detect and contain threats before sensitive data leaves your network.
000
BC Security @bcsecurity.bsky.social · 09/10/2025
Cybersecurity Awareness Month!!! Cyber Tip: Review your PowerShell logs regularly. Attackers often abuse built-in tools like PowerShell to run commands, move laterally, and hide activity. Detailed logging helps spot unusual scripts or commands that may signal an intrusion before it spreads.
000
BC Security @bcsecurity.bsky.social · 08/10/2025
Cybersecurity Awareness Month!!! Cyber Tip: Check file hashes before installing or running downloads. Verifying the SHA256 or MD5 ensures the file hasn’t been tampered with and matches the official source. This quick step helps prevent malware from slipping in through fake or modified installers.
010
BC Security @bcsecurity.bsky.social · 06/10/2025
Cybersecurity Awareness Month!!! Cyber Tip: Use DNS filtering to block malicious domains before they reach your network. Even if someone clicks a bad link, DNS filters can stop the connection, prevent data theft, and reduce overall risk. #Cybersecurity
010
BC Security @bcsecurity.bsky.social · 02/10/2025
Cybersecurity Awareness Month! Cyber Tip: Never enable macros on documents from unknown or untrusted sources. Attackers often send Word/Excel files that trick you into clicking “Enable Content” to launch malware. If you weren’t expecting the file, don’t trust it.
010
BC Security @bcsecurity.bsky.social · 01/10/2025
Happy Cybersecurity Awareness Month!! We believe awareness is the first line of defense. This month, we’ll share tips and insights from our experts to help protect what matters most. Tip: Scammers use urgent language to create panic. Don’t rush, pause & verify before acting.
000
BC Security @bcsecurity.bsky.social · 30/09/2025
One of our Black Hat instructors analyzes a real phishing email, how it works, the red flags, and how to stay safe. youtu.be/IFy_96Dg__E?... #Phishing #SecurityAwareness #Infosec
youtu.be
Did I Just Fall for a Phishing Attempt?
In this video, I walk through a scam email notifying me that someone attempted to log into my Twitter account and I needed to authenticate to ensure I hadn't been compromised.
000
BC Security @bcsecurity.bsky.social · 24/09/2025
PyPI is warning about a new phishing scam hitting package maintainers. Fake “account verification” emails are floating around, pointing to pypi-mirror[.]org, a fake site built to steal your login. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
PyPI urges users to reset credentials after new phishing attacks
The Python Software Foundation has warned victims of a new wave of phishing attacks using a fake Python Package Index (PyPI) website to reset credentials.
000
BC Security @bcsecurity.bsky.social · 09/09/2025
“When ‘working as intended’ means leaking sensitive data” Our analyst Andrew, discovered unauthenticated access to thousands of files and faced roadblocks trying to report it. His blog breaks down what happened and why design flaws matter as much as exploits. bc-security.org/when-intende...
000
BC Security @bcsecurity.bsky.social · 01/09/2025
Hot dogs, cold drinks, and… popping shells? This Labor Day, we’re serving up a special Empire Ops 1 Discount. Attackers don’t take holidays, and neither should your defenses. training.bc-security.org/courses/empi... #Cybersecurity #RedTeam
010
BC Security @bcsecurity.bsky.social · 27/08/2025
@Micrososft highlights top PRC tactics: cloud account abuse (impossible travel, new principals), LOTL lateral movement with psexec/WMI/remote PowerShell, and persistence via web shells on IIS, SharePoint, VPNs, and firewalls. Defenses: MFA, block legacy protocols, hardened configs.
000
BC Security @bcsecurity.bsky.social · 25/08/2025
We are honored to be at #DAFITC this year and catch the keynote from Huntress’ CEO. A powerful discussion on how cybercriminals are abusing tools like ScreenConnect and why defenders must stay vigilant. Great insights for everyone in cyber defense. #CyberSecurity
000
BC Security @bcsecurity.bsky.social · 22/08/2025
AMA starts in a few hours! Jake Krasnov (BC Security) is hosting a LIVE AMA on r/SolarDIY at 12 PM ET — only a few hours from now! Bring your cyber questions here: reddit.com/r/SolarDIY
000