geech @captaingee.ch · 08/11/2025k being “call stack” in windbg and “kill process” in lldb is a cruel, cruel collision. Thanks Tim apple 000
geech @captaingee.ch · 12/10/2025even wearing my flynn's arcade shirt to the theater wasn't enough to save that movie ;( great vfx, great soundtrack, bad movie. long live tron: legacy, the only sequel to tron. 000
geech @captaingee.ch · 29/09/2025when i find who wrote iso 32000 7.6.4.3.3/.4 - i'm not mad, i just want to talk #flareonmedia.tenor.comshrek is standing next to a donkey in the forestALT: shrek is standing next to a donkey in the forest 000
geech @captaingee.ch · 30/08/2025if i see someone wearing these i'm going to respectfully and politely hulk smash them (the glasses) into the sidewalk 010
geech @captaingee.ch · 14/08/2025"ai is going to change everything" dawg this is a bunch of "while true; do curl xxxxxxxxxx" 010
geech @captaingee.ch · 02/08/2025threw together a quick first blood discord bot for CTFd for an event im hosting next week gist.github.com/captainGeech...gist.github.comctfd_first_blood_bot.pyGitHub Gist: instantly share code, notes, and snippets. 000
geech @captaingee.ch · 30/07/2025working on a simple web chal and was too lazy to write the ui myself, gemini almost turned this into a second challenge 🙃 age of llm==age of free xss? 020
geech @captaingee.ch · 16/07/2025I wrote a new blog with Mandiant IR + FLARE on some new intrusion activity by a group we track as UNC6148, likely using a mix of n-day and 0-day exploits to compromise SonicWall SMA 100 series VPN appliances. They have some nifty post-exploitation tooling as well cloud.google.com/blog/topics/...cloud.google.comOngoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud BlogA financially-motivated threat actor is targeting fully patched end-of-life SonicWall devices to deploy a backdoor known as OVERSTEP. 020
geech @captaingee.ch · 06/07/2025the true GOATmedia.tenor.coma group of men standing on a race track with a yellow sign that says huuuulkkkkkALT: a group of men standing on a race track with a yellow sign that says huuuulkkkkk 010
geech @captaingee.ch · 05/07/2025(this is even more egregious and frustrating when you do it for internal tools) 000
geech @captaingee.ch · 05/07/2025if you need to use AggresIve styling, dark patterns, popups, and anti-user defaults to get people to use your new features, maybe they are not good features :) 121
geech @captaingee.ch · 01/07/2025there is something so satisfying about writing rop chains, idk what it is, just a super fun puzzle 020
geech @captaingee.ch · 05/06/2025Picked a bad day to wear my Corellium t-shirt smh ☠️ techcrunch.com/2025/06/05/p...techcrunch.comPhone unlocking firm Cellebrite to acquire mobile testing startup Corellium for $170M | TechCrunchCellebrite said the deal will help with the "accelerated identification of mobile vulnerabilities and exploits." 000
Reposted by geechWesley Shields @wxs.bsky.social · 07/05/2025I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it. cloud.google.com/blog/topics/...cloud.google.comCOLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud BlogRussian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets. 11714
geech @captaingee.ch · 26/04/2025why more JS engines don't have a native bogosort implementation is truly a wonder 000
geech @captaingee.ch · 01/04/2025"And this is why using AppContainer with a packaged app is easier" screw you microsoft i do what i want learn.microsoft.com/en-us/window... 010
geech @captaingee.ch · 31/03/2025if you despise using Visual Studio as much as i do, here you go github.com/captainGeech...github.comwinnativetemplate/Makefile at main · captainGeech42/winnativetemplateTemplate repo for using Make to compile simple win32/MSVC code - captainGeech42/winnativetemplate 000
geech @captaingee.ch · 27/03/2025Too many OPSEC experts out there, I’m an OOPSEC expert. Lmk if you need help adding The Atlantic to YOUR pc small group chats. Signal and more! 050
geech @captaingee.ch · 09/03/2025hey microsoft, hot take, what if you didnt push ads for random games in your fucking operating system as notifications 070
geech @captaingee.ch · 07/03/2025diaphora vs vmware-vmx meanwhile, me watching:media.tenor.coma child is doing a handstand on a swing over a puddle of waterALT: a child is doing a handstand on a swing over a puddle of water 000
geech @captaingee.ch · 02/03/2025lmfao this worked perfectly. thank you to "brute force to make up for my lack of brain cells" 010
geech @captaingee.ch · 02/03/2025reverse engineering and thinking about reducing problem spaces to hit vulnerable code paths is hard. fuzzing however, is both "easy" and "fast" - lazy ftw (may work, may not work, we'll see. need a @digitalocean.com sponsorship lol) 010
geech @captaingee.ch · 01/03/2025my arch laptop hasnt crashed once since districtcon and has been busy since then, so im just going to chalk it up to "cold dark room is scary to gnome" and pretend this never happened see you at the next talk where it will inevitably happen again 000
geech @captaingee.ch · 22/02/2025Now that my @districtcon.bsky.social talk is over, here is the official open-source release of implant.js! I think this represents a notable advancement in the state of the art for modular CNO implant frameworks. Lots of detection info included as well. github.com/captainGeech...github.com 0133
geech @captaingee.ch · 18/02/2025today i used a debugger so bad that you have to nop sled it when inserting breakpoints to ensure they get hit in the place you want. yes i wrote the debugger but thats besides the point 110
geech @captaingee.ch · 16/02/2025If you want your own IDA sticker, come find me @districtcon.bsky.social ;) 050
geech @captaingee.ch · 15/02/2025This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it. LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis. www.cyfirma.com/research/cl0...cyfirma.comCL0P Ransomware : Latest Attacks - CYFIRMAINTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The... 152
Reposted by geechDistrictCon @districtcon.bsky.social · 21/01/2025We're officially 1 month away from DistrictCon Year 0! Check out our agenda for talks, exploits, round tables, and more! www.districtcon.org/agendadistrictcon.orgAgenda — DistrictCon 11512
geech @captaingee.ch · 03/12/2024new startup idea: "Rate my API" you send me your spec and i tell you how bad it is. only $300/hr its like mckinsey for your swagger docs. "lay off 20% of your endpoints" 010
geech @captaingee.ch · 03/12/2024Primarily on invoking mutations and passing data back and forth, it always gets messier than a REST API 110
geech @captaingee.ch · 03/12/2024I find the core premise of GQL interesting, but the services I’ve used that leverage GQL instead of REST are always incredibly painful to use in actuality. Not sure if this is just an unfortunate trend in the implementations or just a lack of comfort on my part, but it’s a notable trend for sure. 110
geech @captaingee.ch · 01/12/2024I will be speaking at #DistrictConYear0 on some interesting modular implant development I've been doing, hope to see you all there! 050