Sign in

domchell.bsky.social

@domchell.bsky.social
237 followers 115 following 5 posts
PostsRepliesMedia
Reposted by @domchell.bsky.social
SpecterOps @specterops.io · 25/02/2026
If a host is compromised, what risk does that data represent? Nemesis 2.2 helps answer that. ✅ Large container processing ✅ Host-based reporting ✅ AI-assisted triage ✅ Full Chromium DPAPI handling Read @harmj0y.bsky.social + @tifkin.bsky.social's latest blog post: ghst.ly/4l2DDbl
ghst.ly
Nemesis 2.2 - SpecterOps
Nemesis 2.2 introduces large disk image processing, LLM agents for automated finding triage and credential analysis, full Chromium DPAPI decryption support, host reporting, and significant performance...
021
Reposted by @domchell.bsky.social
outflank.bsky.social @outflank.bsky.social · 19/02/2026
The macOS Hardened Runtime isn’t a dead end for in-memory execution. In his latest post, Kyle Avery looks at the 'allow-jit' entitlement and demonstrates shellcode execution in apps that have it. www.outflank.nl/blog/2026/02/19/mac…
042
Reposted by @domchell.bsky.social
vx-underground (automated mirror) @vxundergroundre.bsky.social · 14/01/2026
I'd like to thank all of our sponsors for 2025. I'd also really, really, really, want to thank @MDSecLabs, @TrustedSec, @TorGuard, ... and all the individual donors. Thanks to you, I don't need to beg for money on the internet and can focus on kitty cat pictures and malware.
0121
Reposted by @domchell.bsky.social
Emeric Nasi @emericnasi.bsky.social · 17/09/2025
Binary injection vulnerabilities can be found in many MacOS apps. Those may be abused to bypass EDR, hide backdoor, access memory, or bypass TCC! DarwinOps provides - An advanced injection vulnerability scanner - A redteam scenario to exploit them #redteam blog.balliskit.com/macos-dylib-...
blog.balliskit.com
macOS DYLIB Injection at Scale: Designing a Self-Sufficient Loader
Let’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection)
042
Reposted by @domchell.bsky.social
harmj0y @harmj0y.bsky.social · 16/09/2025
Lots of cool new Nemesis features merging in soon from @tifkin_ and I! Development definitely didn't stop with the 2.0 release :) github.com/SpecterOps/N...
github.com
GitHub - SpecterOps/Nemesis: An offensive data enrichment pipeline
An offensive data enrichment pipeline. Contribute to SpecterOps/Nemesis development by creating an account on GitHub.
051
Reposted by @domchell.bsky.social
Phrack Zine @phrack.org · 12/09/2025
Thanks for the excellent writeup @intel471.bsky.social www.intel471.com/blog/the-phr...
intel471.com
The Phrack leak: Examining an APT’s workstation
In August 2025, two anonymous researchers released 9 GB of data from a workstation of a likely advanced persistent threat (APT) group. Here’s an analysis of the data by Intel 471’s Cyber Geopolitical ...
0195
Reposted by @domchell.bsky.social
Clément Labro @itm4n.bsky.social · 15/06/2025
🆕 New blog post! "Offline Extraction of Symantec Account Connectivity Credentials (ACCs)" Following my previous post on the subject, here is how to extract ACCs purely offline. 👉 itm4n.github.io/offline-extr... #redteam #pentesting
Screenshot showing the output of the proof-of-concept tool "SMAStorageDump", where ACCs are dully decrypted.
3114
Reposted by @domchell.bsky.social
FalconForce @falconforce.nl · 11/04/2025
We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them. falconforce.nl/dawshund-fra... #blueteaming #redteaming
1103
domchell.bsky.social @domchell.bsky.social · 09/04/2025
Our red team is growing and we have a rare open position for a Principal RT Operator - if this sounds like you, get in touch 🙏
043
Reposted by @domchell.bsky.social
bohops @bohops.bsky.social · 25/03/2025
[Blog] This ended up being a great applied research project with my co-worker Dylan Tran on weaponizing a technique for fileless DCOM lateral movement based on the original work of James Forshaw. Defensive recommendations provided. - Blog: ibm.com/think/news/f... - PoC: github.com/xforcered/Fo...
ibm.com
Fileless lateral movement with trapped COM objects | IBM
New research from IBM X-Force Red has led to the development of a proof-of-concept fileless lateral movement technique by abusing trapped Component Object Model (COM) objects. Get the details.
01511
Reposted by @domchell.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 16/03/2025
Prodaft has published a technical analysis of Anubis, a new Python-based backdoor linked to Savage Ladybug (FIN7) operations catalyst.prodaft.com/public/repor...
082
Reposted by @domchell.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 11/03/2025
The Blind Eagle APT group has compromised over 1,600 victims inside Colombian institutions and government agencies. The campaign took place in November & December of last year and used an exploit similar to a zero-day exploited by Russian hackers in Ukraine. research.checkpoint.com/2025/blind-e...
research.checkpoint.com
Blind Eagle: …And Justice for All - Check Point Research
Key Points Introduction APT-C-36, also known as Blind Eagle, is a threat group that engages in both espionage and cybercrime. It primarily targets organizations in Colombia and other Latin American co...
086
Reposted by @domchell.bsky.social
Andrea P @decoder-it.bsky.social · 14/03/2025
KrbRelayEx-RPC tool is out! 🎉 Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;) github.com/decoder-it/K...
github.com
GitHub - decoder-it/KrbRelayEx-RPC
Contribute to decoder-it/KrbRelayEx-RPC development by creating an account on GitHub.
0910
Reposted by @domchell.bsky.social
Mehmet Ergene @cyb3rmonk.bsky.social · 14/03/2025
🚨 Detect C2 Beacons! New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection! 🔗 academy.bluraven.io/blog/beaconi... #ThreatHunting #DetectionEngineering #MDE
academy.bluraven.io
C2 Beaconing Detection with MDE Aggregated Report Telemetry
Detecting C2 Beaconing using MDE Aggregated Report Telemetry.
083
Reposted by @domchell.bsky.social
Dirk-jan @dirkjanm.io · 20/02/2025
It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.
0299