Sign in

Cas van Cooten

@casvancooten.com
605 followers 122 following 61 posts

@chvancooten on the bird app 🐦 --- Benevolently malicious offensive security enthusiast || OffSec Developer & Malware Linguist || NimPlant & NimPackt author || @ABNAMRO Red Team

PostsRepliesMedia
Cas van Cooten @casvancooten.com · 25/04/2025
Not thinking about infosec for a while 🥰
6270
Cas van Cooten @casvancooten.com · 18/04/2025
BTW - I don't see this as a vulnerability. It is (clearly) by design, just something to be cautious with for all the vibe coders out there :) The @vscode.dev is doing an excellent job here - they even disable Copilot entirely in untrusted (restricted) workspaces.
010
Cas van Cooten @casvancooten.com · 18/04/2025
quack.py needs work still
010
Cas van Cooten @casvancooten.com · 18/04/2025
10/10 no notes, excellent blending in
221
Cas van Cooten @casvancooten.com · 18/04/2025
Pretty fun proof of concept - VS Code's `copilot-instructions.md` allows for blatant backdooring of agents if any AI agents or edits are run from an untrusted repository. It can seemingly fulfil the user's request, but actually implement (and hide) some nefarious side activities 😂
160
Cas van Cooten @casvancooten.com · 12/04/2025
Very glad I'm not going - at least for this year. We'll see if (or when?) this situation crystallizes out 😅
110
Cas van Cooten @casvancooten.com · 01/04/2025
This is actually so good 👌
000
Cas van Cooten @casvancooten.com · 31/03/2025
Yes! Already made plans to link up 🙌
100
Cas van Cooten @casvancooten.com · 31/03/2025
Touched down in Singapore! Looking forward to Black Hat Asia. Hope to see many of you around!
140
Cas van Cooten @casvancooten.com · 18/03/2025
This must be the most informative graphic contained in the Microsoft docs learn.microsoft.com/en-us/opensp...
A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server
161
Cas van Cooten @casvancooten.com · 12/03/2025
Doing it out of spite. Love it! 😂
110
Cas van Cooten @casvancooten.com · 12/03/2025
Yeah on sunny days I sometimes get 15-20kWh from my panels of which almost everything is returned to grid 😅. I guess it's not really about that number though, but more the question "does 2.7kWh last you until the next sunrays" maybe. And the 800W extra is nice to cover peak usage that exceeds solar
110
Cas van Cooten @casvancooten.com · 12/03/2025
Good stuff! Definitely subscribing to your opinions on it in the future 😂. 2.7kWh ain't much but it's enough to bridge the night on solar I guess!
110
Cas van Cooten @casvancooten.com · 12/03/2025
I've been keeping an eye on these! What is your experience so far? Seems like a great solution in between nothing and a ridiculously expensive all-out battery setup. Too much uncertainty regarding saldering for me to buy anything yet tho 😂
100
Cas van Cooten @casvancooten.com · 09/03/2025
Truly mask off at this point.. it's saddening
010
Cas van Cooten @casvancooten.com · 08/03/2025
I was invited to present Nimplant at Black Hat Asia 2025 in Singapore this April! If you're around, please do reach out to talk offensive development, modern programming languages, or how to use (or detect) Nimplant in your ops. Looking forward to it! www.blackhat.com/asia-25/arse...
000
Cas van Cooten @casvancooten.com · 01/03/2025
That's very cool! I briefly looked into adding plugins the "classical" way as well but backdooring an existing one seems much cleaner. Nice post!
000
Cas van Cooten @casvancooten.com · 28/02/2025
Recently came across a pretty neat technique to silently load (malicious) VS Code extensions using its bootstrapping and portability features. Thought it was interesting enough to warrant my first blog post in 4 years 🙃 Check it out 👇 casvancooten.com/posts/2025/0...
casvancooten.com
Abusing VS Code's Bootstrapping Functionality To Quietly Load Malicious Extensions
Wow, been a while since my last blog 😅. During some research I came across a technique variation which I felt was interesting enough to share in a brief blog post. It relates to how the bootstrapping ...
063
Cas van Cooten @casvancooten.com · 13/01/2025
Leuk Johannes, dank!
000
Cas van Cooten @casvancooten.com · 02/01/2025
Haha yeah this sounds familiar 😅. The smaller the feature the more bugs will pop up 😂
010
Cas van Cooten @casvancooten.com · 02/01/2025
Great updates! Thanks for sticking with the maintenance, still very useful in work automations! 🔥
120
Cas van Cooten @casvancooten.com · 23/12/2024
First day back after leave, man does my brain feel the same trying to remember what all I did before 😂😂
000
Cas van Cooten @casvancooten.com · 08/12/2024
Thumb 11/10, will definitely watch first thing after holiday 😂
030
Cas van Cooten @casvancooten.com · 02/12/2024
media.tenor.com
a puppet master poster shows a hand holding a puppet on strings
ALT: a puppet master poster shows a hand holding a puppet on strings
020
Cas van Cooten @casvancooten.com · 02/12/2024
Lol 75% thought leader, must be because I interact with @xpnsec.com too much 😂 blueskyroast.com/roast/casvan...
150
Cas van Cooten @casvancooten.com · 01/12/2024
let's goooo
media.tenor.com
a group of people are screaming and laughing in a crowd
ALT: a group of people are screaming and laughing in a crowd
000
Cas van Cooten @casvancooten.com · 28/11/2024
Agreed, they're so much fun as a collectible.. maybe we should start re-using badges, new badge for first-time con visitors, firmware update for existing badge holders? 😂
120
Cas van Cooten @casvancooten.com · 26/11/2024
I think it's the latter for most? Less frustrations with the platform maybe, and/or not willing to juggle multiple platforms (temporarily) potentially
010
Cas van Cooten @casvancooten.com · 26/11/2024
Unfortunately there are still too many capable and informative folks on there :(. At least to the degree I'm not comfortable burning my account with fire just yet. @xpnsec.com is doing a great job with influencing everyone to move over here, though!
210
Cas van Cooten @casvancooten.com · 26/11/2024
My ears were ringing when this was presented at RedTreat. Time for round two with this blog and tool release 😅 🔥
110
Cas van Cooten @casvancooten.com · 26/11/2024
@whataweekhuh.bsky.social vibes
000
Cas van Cooten @casvancooten.com · 25/11/2024
Damn, 10ms for an 9B lookup sounds very impressive 🫨. Do you have any engineering blogs anywhere where you cover the architecture in more detail?
100
Cas van Cooten @casvancooten.com · 23/11/2024
It's insane! Same vibes as the North Korean actor that spent so much time and effort (and AI credits) getting legitimately hired only to instantly set off malware alerts when they got their laptop 😭 all that setup effort wasted lmao whyy
110
Cas van Cooten @casvancooten.com · 22/11/2024
Dear network, I tried so hard and got so far, but in the end having 2000+ connections doesn't even matter. Agree? 👍
160
Cas van Cooten @casvancooten.com · 22/11/2024
Oh man I love quiet posters! That's a quality feed. Thanks for that! Loving the "bring your own algorithm" functionality on here 🔥
010
Cas van Cooten @casvancooten.com · 21/11/2024
Yeah I definitely agree. In my mind it helps me "mentally pronounce" sentences at the right pace and intonation, but that might just be because I'm not a native speaker lol
010
Cas van Cooten @casvancooten.com · 21/11/2024
Missing comma? Prepare for a heated argument with said manager then 🤭 writer.com/blog/oxford-...
writer.com
Oxford comma: is it necessary?
We cover the basics that you need to know about the use of the Oxford comma, including examples of the correct and incorrect way to use it.
110
Cas van Cooten @casvancooten.com · 20/11/2024
Gonna yeet me some skeets about thrunting real soon
040
Cas van Cooten @casvancooten.com · 20/11/2024
Man I really hope this trend continues past critical mass, and there's no "bounce-back" like with mastodon or threads 🤞
020
Cas van Cooten @casvancooten.com · 20/11/2024
Gonna burn some elite tradecraft out of insecurity
160
Cas van Cooten @casvancooten.com · 19/11/2024
media.tenor.com
a man in a suit and tie says it 's happening with his arms in the air
ALT: a man in a suit and tie says it 's happening with his arms in the air
030
Cas van Cooten @casvancooten.com · 19/11/2024
Looks like @rasta-mouse.bsky.social made it 👀 @xpnsec.com
351
Cas van Cooten @casvancooten.com · 19/11/2024
Actually the $5 wrench method is easy to pull off lol. Also easy to end up in jail 😂
110
Cas van Cooten @casvancooten.com · 19/11/2024
Least resistance != easy 😁 Sure it can be done with the right level of determination, but in 90%+ of cases criminals want more scalable attacks. Decent security practices should keep you protected against those easily!
media.tenor.com
a man in a white shirt is standing in front of a building with a quote .
Alt: Nobody said it was easy song gif
120
Cas van Cooten @casvancooten.com · 19/11/2024
Path of least resistance, social engineer target to install stealer malwarez on the MacBook, stay away from the iPhone 😂 Alternatively, the $5 wrench method
110
Cas van Cooten @casvancooten.com · 18/11/2024
That's my password, no leak pls :(
010
Cas van Cooten @casvancooten.com · 18/11/2024
Ahaha who knows! I'll make sure to wear a name tag 👀
120
Cas van Cooten @casvancooten.com · 18/11/2024
I know, it was just a way for me to mock your volcano-tier heating preferences lol 🌋
020
Cas van Cooten @casvancooten.com · 18/11/2024
21.5 what the heck!! This better be in Fahrenheit
100
Cas van Cooten @casvancooten.com · 17/11/2024
Hello world! With Bluesky picking up steam I guess a (re-)introduction is in order. My name is Cas, I'm a red teamer at a big bank in the Netherlands. I like malware development (specifically in modern languages like Rust or Go) and learning more dev stuff every day. Content may include shitposts! 💜
3392