Sign in

geech

@captaingee.ch
119 followers 132 following 43 posts

cybercrime connoisseur && exploitz engineering enthusiast | synapse fanboy | second breakfast enthusiast

PostsRepliesMedia
geech @captaingee.ch · 08/11/2025
k being “call stack” in windbg and “kill process” in lldb is a cruel, cruel collision. Thanks Tim apple
000
geech @captaingee.ch · 29/10/2025
All Azure users are hereby authorized to start Halloween early
010
geech @captaingee.ch · 12/10/2025
even wearing my flynn's arcade shirt to the theater wasn't enough to save that movie ;( great vfx, great soundtrack, bad movie. long live tron: legacy, the only sequel to tron.
000
geech @captaingee.ch · 29/09/2025
when i find who wrote iso 32000 7.6.4.3.3/.4 - i'm not mad, i just want to talk #flareon
media.tenor.com
shrek is standing next to a donkey in the forest
ALT: shrek is standing next to a donkey in the forest
000
geech @captaingee.ch · 30/08/2025
if i see someone wearing these i'm going to respectfully and politely hulk smash them (the glasses) into the sidewalk
010
geech @captaingee.ch · 14/08/2025
"ai is going to change everything" dawg this is a bunch of "while true; do curl xxxxxxxxxx"
010
geech @captaingee.ch · 02/08/2025
threw together a quick first blood discord bot for CTFd for an event im hosting next week gist.github.com/captainGeech...
gist.github.com
ctfd_first_blood_bot.py
GitHub Gist: instantly share code, notes, and snippets.
000
geech @captaingee.ch · 30/07/2025
working on a simple web chal and was too lazy to write the ui myself, gemini almost turned this into a second challenge 🙃 age of llm==age of free xss?
020
geech @captaingee.ch · 16/07/2025
I wrote a new blog with Mandiant IR + FLARE on some new intrusion activity by a group we track as UNC6148, likely using a mix of n-day and 0-day exploits to compromise SonicWall SMA 100 series VPN appliances. They have some nifty post-exploitation tooling as well cloud.google.com/blog/topics/...
cloud.google.com
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud Blog
A financially-motivated threat actor is targeting fully patched end-of-life SonicWall devices to deploy a backdoor known as OVERSTEP.
020
geech @captaingee.ch · 10/07/2025
Signal sticker pack metadata is fun signal.art/addstickers/...
010
geech @captaingee.ch · 06/07/2025
the true GOAT
media.tenor.com
a group of men standing on a race track with a yellow sign that says huuuulkkkkk
ALT: a group of men standing on a race track with a yellow sign that says huuuulkkkkk
010
geech @captaingee.ch · 05/07/2025
if you need to use AggresIve styling, dark patterns, popups, and anti-user defaults to get people to use your new features, maybe they are not good features :)
121
geech @captaingee.ch · 01/07/2025
there is something so satisfying about writing rop chains, idk what it is, just a super fun puzzle
020
geech @captaingee.ch · 05/06/2025
Picked a bad day to wear my Corellium t-shirt smh ☠️ techcrunch.com/2025/06/05/p...
techcrunch.com
Phone unlocking firm Cellebrite to acquire mobile testing startup Corellium for $170M | TechCrunch
Cellebrite said the deal will help with the "accelerated identification of mobile vulnerabilities and exploits."
000
Reposted by geech
Wesley Shields @wxs.bsky.social · 07/05/2025
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it. cloud.google.com/blog/topics/...
cloud.google.com
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
11714
geech @captaingee.ch · 26/04/2025
why more JS engines don't have a native bogosort implementation is truly a wonder
000
geech @captaingee.ch · 01/04/2025
"And this is why using AppContainer with a packaged app is easier" screw you microsoft i do what i want learn.microsoft.com/en-us/window...
010
geech @captaingee.ch · 31/03/2025
if you despise using Visual Studio as much as i do, here you go github.com/captainGeech...
github.com
winnativetemplate/Makefile at main · captainGeech42/winnativetemplate
Template repo for using Make to compile simple win32/MSVC code - captainGeech42/winnativetemplate
000
geech @captaingee.ch · 27/03/2025
Too many OPSEC experts out there, I’m an OOPSEC expert. Lmk if you need help adding The Atlantic to YOUR pc small group chats. Signal and more!
050
geech @captaingee.ch · 09/03/2025
hey microsoft, hot take, what if you didnt push ads for random games in your fucking operating system as notifications
070
geech @captaingee.ch · 07/03/2025
diaphora vs vmware-vmx meanwhile, me watching:
media.tenor.com
a child is doing a handstand on a swing over a puddle of water
ALT: a child is doing a handstand on a swing over a puddle of water
000
geech @captaingee.ch · 04/03/2025
arrested development season 1 is the true peak of comedy
020
geech @captaingee.ch · 02/03/2025
lmfao this worked perfectly. thank you to "brute force to make up for my lack of brain cells"
010
geech @captaingee.ch · 02/03/2025
reverse engineering and thinking about reducing problem spaces to hit vulnerable code paths is hard. fuzzing however, is both "easy" and "fast" - lazy ftw (may work, may not work, we'll see. need a @digitalocean.com sponsorship lol)
010
geech @captaingee.ch · 01/03/2025
my arch laptop hasnt crashed once since districtcon and has been busy since then, so im just going to chalk it up to "cold dark room is scary to gnome" and pretend this never happened see you at the next talk where it will inevitably happen again
000
geech @captaingee.ch · 23/02/2025
Department of Government Efficiency
030
geech @captaingee.ch · 22/02/2025
Now that my @districtcon.bsky.social talk is over, here is the official open-source release of implant.js! I think this represents a notable advancement in the state of the art for modular CNO implant frameworks. Lots of detection info included as well. github.com/captainGeech...
github.com
0133
geech @captaingee.ch · 18/02/2025
today i used a debugger so bad that you have to nop sled it when inserting breakpoints to ensure they get hit in the place you want. yes i wrote the debugger but thats besides the point
110
geech @captaingee.ch · 16/02/2025
If you want your own IDA sticker, come find me @districtcon.bsky.social ;)
050
geech @captaingee.ch · 15/02/2025
This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it. LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis. www.cyfirma.com/research/cl0...
cyfirma.com
CL0P Ransomware : Latest Attacks - CYFIRMA
INTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The...
152
geech @captaingee.ch · 14/02/2025
c plus plus, more like c plus sucks
000
Reposted by geech
DistrictCon @districtcon.bsky.social · 21/01/2025
We're officially 1 month away from DistrictCon Year 0! Check out our agenda for talks, exploits, round tables, and more! www.districtcon.org/agenda
districtcon.org
Agenda — DistrictCon
11512
geech @captaingee.ch · 03/12/2024
new startup idea: "Rate my API" you send me your spec and i tell you how bad it is. only $300/hr its like mckinsey for your swagger docs. "lay off 20% of your endpoints"
010
geech @captaingee.ch · 02/12/2024
graphql, more like garbageql
130
geech @captaingee.ch · 01/12/2024
I will be speaking at #DistrictConYear0 on some interesting modular implant development I've been doing, hope to see you all there!
050
geech @captaingee.ch · 27/05/2023
hello there
030