Sign in

Marc André Tanner

@brain-dump.org
44 followers 128 following 8 posts

Information security, operating systems, text editors github.com/martanne

PostsRepliesMedia
Marc André Tanner @brain-dump.org · 07/06/2026
My #SOCON2026 talk is online. I cover how DevOps platforms like GitLab become key junctions in identity-based attack paths: secret exposure, cross-cloud OIDC federation, over privileged runners and bots. Also: lots of "uhms." www.youtube.com/watch?v=La6j...
youtube.com
Mapping GitLab Attack Paths into BloodHound with OpenGraph | SO-CON 26
YouTube video by SpecterOps
031
Reposted by Marc André Tanner
Compass Security @compass-security.com · 03/03/2026
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
043
Marc André Tanner @brain-dump.org · 14/11/2025
Last week presented at an university alumni event, this week successfully used during a red teaming engagement.
Bitpixie presentation
010
Reposted by Marc André Tanner
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025
🧭 Navigation complete! The team from Compass Security just charted a course straight into @home_assistant Green at #Pwn2Own. They head off to the disclosure room to spill how they did it. #P2OIreland
053
Marc André Tanner @brain-dump.org · 18/05/2025
Now merged into Certipy 5.0.2
020
Marc André Tanner @brain-dump.org · 13/05/2025
Curious why I was rebooting random laptops? Credit goes to Rairii for the original research and Thomas from @neodyme.io for the initial PoC.
140
Marc André Tanner @brain-dump.org · 11/04/2025
Last week I had a fantastic experience at @specterops.bsky.social's #SOCON2025 and subsequent IDOT training. It was a great opportunity to get in touch with leading experts. Apparently I also bugged them enough to merge my small BloodHound contribution. github.com/SpecterOps/B...
SOCON swag
081
Marc André Tanner @brain-dump.org · 17/02/2025
www.microsoft.com/en-us/securi...
microsoft.com
Storm-2372 conducts device code phishing campaign | Microsoft Security Blog
Microsoft Threat Intelligence Center discovered an active and successful device code phishing campaign by a threat actor we track as Storm-2372. Our ongoing investigation indicates that this campaign ...
110
Reposted by Marc André Tanner
Compass Security @compass-security.com · 11/02/2025
Avoid LDAP monitoring by leveraging local registry data with certipy parse! Check out our latest pull request and read Marc Tanner’s (@brain-dump.org) blog post: blog.compass-security.com/2025/02/stea...
074