Sign in

Drew @hoodoer

@hoodoer.bsky.social
173 followers 241 following 43 posts

AppSec pentester type at Blackthorne Consulting. Beach bum. Super awesome dad. Coder of weird things. github.com/hoodoer

PostsRepliesMedia
Drew @hoodoer @hoodoer.bsky.social · 25/06/2026
I'm Running a @theredteamvillage.bsky.social hands-on "Tactic" session at DEFCON this year. "Post-Exploitation of the Desktop with JS-Tap" covers malicious browser extensions, Electron, & Node implants using new JS-Tap beacons. Repo here: github.com/hoodoer/JS-Tap See you nerds in Vegas.
github.com
GitHub - hoodoer/JS-Tap: JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and maintain persistence. Browser ext...
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and maintain persistence. Browser extension, electron app, ...
000
Drew @hoodoer @hoodoer.bsky.social · 12/06/2026
So excited to finally get this code public, it's been in development for a while. I'll be demoing this at Black Hat Arsenal this year, and there might be additional opportunities to get your hands on it in Vegas.
110
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 03/02/2026
Model Context Protocol servers often rely on SSE and WebSockets, which makes manual testing tricky. @hoodoer.bsky.social introduces MCP-ASD, a new Burp Suite extension designed to help testers identify, enumerate, and interact with MCP servers more effectively. trustedsec.com/blog/mcp-in-...
trustedsec.com
MCP in Burp Suite: From Enumeration to Targeted Exploitation
022
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 30/01/2026
Microsoft seems to be integrating #Copilot into everything. And we mean EVERYTHING. Find out what we have to say about it and how it relates to data security on the latest episode of the #SecurityNoise podcast! @hoodoer.bsky.social youtu.be/QsmdLJsvAkc
031
Drew @hoodoer @hoodoer.bsky.social · 20/01/2026
Nice to finally knock this off my to-do list. Hope it helps!
010
Drew @hoodoer @hoodoer.bsky.social · 13/06/2025
The path to tricking users to trigger this isn't so hard.
000
Drew @hoodoer @hoodoer.bsky.social · 14/05/2025
Yes!
media.tenor.com
the words it 's the most wonderful time of the year are written in red
ALT: the words it 's the most wonderful time of the year are written in red
021
Drew @hoodoer @hoodoer.bsky.social · 29/04/2025
I use "what's my IP" sites a ton to check my routing, got tired of bloated sites. Made a simple service for this: checkip.sh or checkip.sh?ip=8.8.8.8 Command line too (-L needed): curl -L checkip.sh/cli or for a specific IP instead of your source IP: curl -L checkip.sh/cli?ip=8.8.8.8
checkip.sh
checkIP.sh
000
Drew @hoodoer @hoodoer.bsky.social · 23/04/2025
Looking forward to showing off the latest features. Hoping to have some fun conversations during the Livestream.
010
Reposted by Drew @hoodoer
Shawn Thomas Photography @understudy77.bsky.social · 12/04/2025
The #eagles are Conowingo at feisty. One eagle catches, 3 more chase and it's fair game to steal food if you can. #birds #eagle #wildlife #photography
1345
Drew @hoodoer @hoodoer.bsky.social · 26/03/2025
I just pushed my private JS-Tap repo changes over to public for v2.2 release. Network obfuscation, rendering improvements, reverse filter searching, and client fingerprinting that isn't completely broken now available. Release notes: github.com/hoodoer/JS-T... Repo: github.com/hoodoer/JS-Tap
github.com
v2.2 Release: Network traffic obfuscation, lazy rendering, reverse filter search option, and fingerprinting fixes · hoodoer JS-Tap · Discussion #36
Development has been in a private branch for a little while, but this is the latest code. Network Obfuscation: You now have the option in app settings to turn on traffic obfuscation. If the browser...
010
Drew @hoodoer @hoodoer.bsky.social · 13/02/2025
This landing page does not inspire confidence in the security posture lol waste.gov
waste.gov
Waste.Gov – Tracking government waste.Waste.Gov – Tracking government waste.
111
Drew @hoodoer @hoodoer.bsky.social · 10/02/2025
This should be fun, this is a great tool.
110
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 07/02/2025
Senior Security Consultant Whitney Phillips will be speaking at CactusCon next week! Her session "Tips and Tricks to Creating Your First Conference Talk" will take place on Feb 14 at 11am in the Career Village. Stop by our booth too if you'll be there! www.cactuscon.com/cc13-schedule
031
Drew @hoodoer @hoodoer.bsky.social · 03/02/2025
Anyone need a @cactuscon.com ticket? I think I have a spare
000
Reposted by Drew @hoodoer
Bruce ("grymoire") Barnett @grymoire.bsky.social · 14/01/2025
The #ShmooCon 2025 talks have been uploaded youtube.com/playlist?lis...
youtube.com
ShmooCon 2025 - YouTube
You can reach me at https://twitter.com/Strong1Wind
02210
Drew @hoodoer @hoodoer.bsky.social · 09/01/2025
See all you fabulous nerds at ShmooCon
160
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 17/12/2024
It's that time of year again! We are excited to reveal our top 10 most read blogs of 2024 🥳 trustedsec.com/blog/top-10-...
trustedsec.com
Top 10 Blogs of 2024
074
Reposted by Drew @hoodoer
Sean @cackalackdev.bsky.social · 05/12/2024
041
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 02/12/2024
Our Business Email Compromise #webinar is this week! Don't miss your chance to learn the basics of BEC analysis from our experts so you can better protect your M365 environment. Register now! trustedsec.zoom.us/webinar/regi...
032
Drew @hoodoer @hoodoer.bsky.social · 28/11/2024
I've never been blue team, but I setup SIEM/XDR in the home lab and I can completely understand falling into an endless chase of increasing visibility into the environment and tweaking on false positives. Kinda addicting.
000
Reposted by Drew @hoodoer
TrustedSec @trustedsec.com · 22/11/2024
So why does Rob have an ATM in his garage? 🤑 Watch the full hardware hacking episode of Security Noise now! youtu.be/ZJXB8NybMHg
youtu.be
Security Noise Ep 7.6 - Ghost in The Machine: Hardware Hacking w/ Rob Simon
YouTube video by TrustedSec
011
Reposted by Drew @hoodoer
Justin Elze @handle.invalid · 18/11/2024
If anyone is looking and does cloud testing recruiting.paylocity.com/Recruiting/J...
recruiting.paylocity.com
TrustedSec - Kubernetes Cloud Pentester / Security Consultant
*Note* TrustedSec will be conducting interviews and filling this position in Q1 2025.TrustedSec is seeking a Kubernetes Cloud Pentester to join our Force-Cloud team and play a critical role ...
12311
Drew @hoodoer @hoodoer.bsky.social · 02/04/2024
I'm excited to get to share the new offensive features of JS-Tap at @cackalackycon.bsky.social. I'll be doing a lengthy demo of all the new toys and tricks in the afternoon on Friday May 17th, hope to see folks at this fantastic conference.
011
Drew @hoodoer @hoodoer.bsky.social · 14/10/2023
Terrifying pitbull
010
Drew @hoodoer @hoodoer.bsky.social · 11/10/2023
I really need to start using this. Who wants to hang out at wild west hacking fest?
020