Sign in

r1cksec

@r1cksec.bsky.social
583 followers 69 following 127 posts

Data breach revealed, Malware lurks, silent, stealthy - OSINT tracks the thread. URLs I post may contain malware – be careful and check yourself before running anything. github.com/r1cksec infosec.exchange/@r1cksec

PostsRepliesMedia
r1cksec @r1cksec.bsky.social · 02/10/2026
A post about publicly exposed MCP servers (147 without authentication). pluto.security/blog/wide-op... #infosec #cybersecurity #osint #shodan #ai
pluto.security
Wide Open: 147 Unauthenticated MCP Servers Exposed | Pluto Security
Pluto Research found 179 exposed MCP servers, including 147 with no authentication. See what attackers could access and how security teams can fix it.
010
r1cksec @r1cksec.bsky.social · 01/10/2026
Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer. github.com/VoidSecSoftw... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - VoidSecSoftwares/voidsyscall: Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.
Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer. - VoidSecSoftwares/voidsyscall
030
r1cksec @r1cksec.bsky.social · 29/09/2026
Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal. github.com/mlcsec/Reset... #infosec #cybersecurity #redteam #pentest #osint #opensource
github.com
GitHub - mlcsec/ResetSpy: Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal
Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal - mlcsec/ResetSpy
030
r1cksec @r1cksec.bsky.social · 28/09/2026
InjectSetConsole performs process code injection by leveraging a Windows named pipe. github.com/TwoSevenOneT... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory
Proof of Concept for Process Code Injection Without Using WriteProcessMemory - TwoSevenOneT/InjectSetConsole
011
r1cksec @r1cksec.bsky.social · 28/09/2026
A single-pass Active Directory enumerator for an anonymous (null) session, using the \samr and \lsarpc named pipes. No credentials required. github.com/crypt0p3g/ad... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - crypt0p3g/adnullenum: One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.
One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output. - crypt0p3g/adnullenum
001
r1cksec @r1cksec.bsky.social · 25/09/2026
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI. github.com/crypt0p3g/dp... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - crypt0p3g/dpapi-toolkit: Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI. - crypt0p3g/dpapi-toolkit
020
r1cksec @r1cksec.bsky.social · 24/09/2026
Tool to authenticate to an LDAP/S server with a certificate through Schannel written in Rust. github.com/g0h4n/PassTh... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - g0h4n/PassTheCert-rs: Tool to authenticate to an LDAP/S server with a certificate through Schannel written in Rust. 🦀
Tool to authenticate to an LDAP/S server with a certificate through Schannel written in Rust. 🦀 - g0h4n/PassTheCert-rs
030
r1cksec @r1cksec.bsky.social · 22/09/2026
OneDrive as a covert C2 transport for Cobalt Strike github.com/nmht3t/OneDr... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - nmht3t/OneDrive-UDC2: OneDrive as a covert C2 transport for Cobalt Strike
OneDrive as a covert C2 transport for Cobalt Strike - nmht3t/OneDrive-UDC2
020
r1cksec @r1cksec.bsky.social · 21/09/2026
Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall github.com/almounah/silph #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - almounah/silph: Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall
Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall - almounah/silph
030
r1cksec @r1cksec.bsky.social · 19/09/2026
A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel. github.com/Whispergate/... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - Whispergate/msteams: Mythic C2 MSTeams Communication Channel
Mythic C2 MSTeams Communication Channel. Contribute to Whispergate/msteams development by creating an account on GitHub.
041
r1cksec @r1cksec.bsky.social · 15/09/2026
Active Directory snapshots from Linux and macOS in the AD Explorer .dat format. Opens in AD Explorer, works with ADExplorerSnapshot.py and BOFHound. github.com/crypt0p3g/ad... #infosec #cybersecurity #redteam #pentest #opensource
adexplorersnapshot.py
050
r1cksec @r1cksec.bsky.social · 14/09/2026
Browse, search and audit AD Explorer snapshots offline in your browser: decoded attributes, LDAP filters, and reports for what BloodHound doesn't show (DNS, subnets, DFS, GPO links, LAPS, AD CS). github.com/crypt0p3g/ad... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - crypt0p3g/adexview: Browse, search and audit AD Explorer snapshots offline in your browser: decoded attributes, LDAP filters, and reports for what BloodHound doesn't show (DNS, subnets, DFS, ...
Browse, search and audit AD Explorer snapshots offline in your browser: decoded attributes, LDAP filters, and reports for what BloodHound doesn't show (DNS, subnets, DFS, GPO links, LAPS, AD CS...
031
r1cksec @r1cksec.bsky.social · 12/09/2026
askWAM requests Microsoft Entra access tokens silently through Windows Web Account Manager (WAM) github.com/dirkjanm/ask... #infosec #cybersecurity #redteam #pentest #cloud #azure #entra
github.com
GitHub - dirkjanm/askWAM: Ask the Web Account Manager (WAM) for Entra ID tokens
Ask the Web Account Manager (WAM) for Entra ID tokens - dirkjanm/askWAM
021
r1cksec @r1cksec.bsky.social · 10/09/2026
An Overview of Shellcode Loaders and an Introduction to Crystal Palace. 0xdbgman.github.io/posts/shellc... #infosec #cybersecurity #redteam #pentest
0xdbgman.github.io
Shellcode Loaders: Advanced Execution & Evasion Tradecraft
Red Teamer & Low-Level Developer. Deep dives into Windows Internals, Kernel Exploitation, Driver Analysis, and Red Team techniques.
040
r1cksec @r1cksec.bsky.social · 09/09/2026
Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. github.com/MSNightmare/... #infosec #cybersecurity #redteam #pentest #windows
github.com
GitHub - MSNightmare/ShieldCrash: Windows Defender 0day Vulnerability
Windows Defender 0day Vulnerability. Contribute to MSNightmare/ShieldCrash development by creating an account on GitHub.
021
r1cksec @r1cksec.bsky.social · 07/09/2026
How WebDav can be used to bypass Smartscreen, and MOTW. g3tsyst3m.com/initial%20ac... #infosec #cybersecurity #redteam #pentest #phishing #windows
g3tsyst3m.com
Using WebDav to Outsmart Smartscreen, MOTW, and that OTHER Alert
The last time I wrote about SmartScreen and MOTW, the focus was a bit divided. I tried my best to blend the use of DLL sideloading with signed binaries packed within a .VHDX mounted disk. In the end...
010
r1cksec @r1cksec.bsky.social · 06/09/2026
A post about how to bypass Chromes remote-debugging port restrictions. www.pikered.com/en/learn/byp... #infosec #cybersecurity #redteam #pentest #chrome
pikered.com
Activating Chrome DevTools Protocol in Memory: Bypassing -remote-debugging-port Restrictions - Pikered
A technical walkthrough of a new offensive technique that activates the Chrome Debugging Protocol directly in memory, bypassing Google's --remote-debugging-port mitigations. Covers chrome.dll signatur...
030
r1cksec @r1cksec.bsky.social · 06/09/2026
A post about how to abuse Windows provisioning packages and what detection opportunities exist (requires elevated permissions). ipurple.team/2026/08/04/p... #infosec #cybersecurity #redteam #pentest
ipurple.team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…
020
r1cksec @r1cksec.bsky.social · 04/09/2026
Materials for Malware Development: Evading EDR from Loaders to the Kernel presented at DEF CON 34 and BSidesLV 2026. Covers EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques. github.com/tyeurada/edr... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - tyeurada/edrEvasionWorkshop: Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware develo...
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasio...
001
r1cksec @r1cksec.bsky.social · 03/09/2026
Blacklight is a cross-platform toolkit for mapping, analyzing, and understanding the local AI agent attack surface across Windows, macOS, and Linux. github.com/SpecterOps/B... #infosec #cybersecurity #redteam #pentest #ai
github.com
GitHub - SpecterOps/Blacklight: Blacklight is a cross-platform toolkit for mapping, analyzing, and understanding the local AI agent attack surface across Windows, macOS, and Linux.
Blacklight is a cross-platform toolkit for mapping, analyzing, and understanding the local AI agent attack surface across Windows, macOS, and Linux. - SpecterOps/Blacklight
000
r1cksec @r1cksec.bsky.social · 02/09/2026
awshound collects AWS IAM/authorization data and builds a BloodHound OpenGraph. github.com/AWSHound/AWS... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - AWSHound/AWSHound: AWS Bloodhound OpenGraph Connector
AWS Bloodhound OpenGraph Connector. Contribute to AWSHound/AWSHound development by creating an account on GitHub.
021
r1cksec @r1cksec.bsky.social · 01/09/2026
New cheatsheets pushed github.com/r1cksec/chea... #infosec #cybersecurity #redteam #pentest #threatintel #malware #dfir #bugbounty #opensource
github.com
GitHub - r1cksec/cheatsheets: Collection of knowledge about information security
Collection of knowledge about information security - r1cksec/cheatsheets
032
r1cksec @r1cksec.bsky.social · 31/08/2026
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data. github.com/NetSPI/AD-Pa... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - NetSPI/AD-PathFinder: Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data. - NetSPI/AD-PathFinder
173
r1cksec @r1cksec.bsky.social · 30/08/2026
Bypass llm guardrails by confusing it with fabricated tool output. github.com/DavidCarliez... #infosec #cybersecurity #redteam #pentest #ai
github.com
GitHub - DavidCarliez/trustmebro: Bypass llm guardrails by confusing it with fabricated tool output.
Bypass llm guardrails by confusing it with fabricated tool output. - DavidCarliez/trustmebro
040
r1cksec @r1cksec.bsky.social · 30/08/2026
If `qvm-copy-to-vm` is used to copy a file from dom0 to a malicious qube, that qube can inject an arbitrary command into dom0. www.qubes-os.org/news/2026/08... #infosec #cybersecurity #linux #qubes
qubes-os.org
QSB-118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting
We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced ...
012
r1cksec @r1cksec.bsky.social · 29/08/2026
Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant) github.com/zer0conditio... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - zer0condition/GoodmansKernel: Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant)
Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant) - zer0condition/GoodmansKernel
020
r1cksec @r1cksec.bsky.social · 28/08/2026
A POC tool for exploring dev-tunnels github.com/xpn/Ouroboros #infosec #cybersecurity #redteam #pentest
github.com
GitHub - xpn/Ouroboros: A POC tool for exploring dev-tunnels
A POC tool for exploring dev-tunnels. Contribute to xpn/Ouroboros development by creating an account on GitHub.
020
r1cksec @r1cksec.bsky.social · 27/08/2026
A full interactive remote desktop delivered entirely through SSH and displayed directly in your terminal. github.com/rylena/sshdesk #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - rylena/sshdesk: A full interactive remote desktop delivered entirely through SSH and displayed directly in your terminal.
A full interactive remote desktop delivered entirely through SSH and displayed directly in your terminal. - rylena/sshdesk
010
r1cksec @r1cksec.bsky.social · 26/08/2026
Hades is a fully-featured cross-platform Chrome Extension agent. Hades is designed for Mythic 3.0 and newer. github.com/MythicAgents... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - MythicAgents/Hades: Hades is a fully-featured cross-platform Chrome Extension agent. Hades is designed for Mythic 3.0 and newer.
Hades is a fully-featured cross-platform Chrome Extension agent. Hades is designed for Mythic 3.0 and newer. - MythicAgents/Hades
020
r1cksec @r1cksec.bsky.social · 25/08/2026
An post that describes how Electron/Node.js can be used for offensive actions c0rnbread.com/playing-a-di... #infosec #cybersecurity #redteam #pentest
c0rnbread.com
Playing a Different Game: Rethinking Modern Defense Evasion
Background Hi, it's been a while. A couple of months ago I was working on some payload development for an upcoming engagement. I needed to bypass a few security products. I was working on a payload...
010
r1cksec @r1cksec.bsky.social · 23/08/2026
A post about how the functionality of dnscmd.exe was ported to a BOF, enabling to gain domain admin rights when impersonating a user who is a member of the DnsAdmins group. blog.paradoxis.nl/playing-arou... #infosec #cybersecurity #redteam #pentest
blog.paradoxis.nl
Playing Around With ADIDNS RPC Internals
TL;DR: I ported the functionality of dnscmd.exe into (slightly) more OPSEC safe Beacon Object Files (BOFs) so you can get domain admin…
113
r1cksec @r1cksec.bsky.social · 22/08/2026
WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. github.com/Arcanum-Sec/... #infosec #cybersecurity #redteam #pentest #xss
github.com
GitHub - Arcanum-Sec/wraith: WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. For authorized security testing, research & education o...
WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. For authorized security testing, research & education only. - Arcanum-Sec/wraith
000
r1cksec @r1cksec.bsky.social · 21/08/2026
Authenticode signature manipulation toolkit for Red Team operations and security research. github.com/KriyosArcane... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file t...
Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic...
030
r1cksec @r1cksec.bsky.social · 20/08/2026
PoC exploit chain (CVE-2026-47301) for SCCM, combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution. github.com/OmriBaso/SCC... #infosec #cybersecurity #pentest #cve #redteam
github.com
GitHub - OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit: Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrar...
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL h...
010
r1cksec @r1cksec.bsky.social · 19/08/2026
A Rust-powered OT/ICS security framework featuring asset discovery, enumeration, controlled validation, simulators, and CLI, TUI, and web interfaces. Discover validate, and try not to cut off the water supply. github.com/Whispergate/... #infosec #cybersecurity #pentest
github.com
GitHub - Whispergate/SCADAVER: SCADAver: a Rust-powered, multi-protocol OT/ICS security framework for authorized labs featuring asset discovery, enumeration, controlled validation, simulators, and CLI...
SCADAver: a Rust-powered, multi-protocol OT/ICS security framework for authorized labs featuring asset discovery, enumeration, controlled validation, simulators, and CLI, TUI, and web interfaces. D...
010
r1cksec @r1cksec.bsky.social · 17/08/2026
Mythic C2 agent with a full in-memory BOF loader for macOS and Linux github.com/ServiceNow/d... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - ServiceNow/Dark-Agent: Mythic C2 agent with a full in-memory BOF loader for macOS and Linux
Mythic C2 agent with a full in-memory BOF loader for macOS and Linux - ServiceNow/Dark-Agent
030
r1cksec @r1cksec.bsky.social · 13/08/2026
Researchers set up a fake startup and hired suspected Lazarus linked IT workers and monitored their activity. any.run/cybersecurit... #infosec #cybersecurity #threatintel
any.run
Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed
See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.
011
r1cksec @r1cksec.bsky.social · 12/08/2026
This repository contains a collection of tools and resources related to the Pass-the-Passkey family of attacks, which target WebAuthn and FIDO2 authentication mechanisms. github.com/SpecterOps/p... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - SpecterOps/pass-the-passkey: Pass-the-Passkey Family of Attacks
Pass-the-Passkey Family of Attacks. Contribute to SpecterOps/pass-the-passkey development by creating an account on GitHub.
020
r1cksec @r1cksec.bsky.social · 11/08/2026
LOLRMM is a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors. lolrmm.io #infosec #cybersecurity #redteam #pentest
lolrmm.io
031
r1cksec @r1cksec.bsky.social · 10/08/2026
pyTGTDeleg abuses the Kerberos delegation mechanism (tgtdeleg trick) to extract a usable forwarded TGT from a domain-joined MSSQL server, using only SA credentials. github.com/ivancabrera0... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - ivancabrera02/pyTGTdeleg
Contribute to ivancabrera02/pyTGTdeleg development by creating an account on GitHub.
001
r1cksec @r1cksec.bsky.social · 08/08/2026
ANIMO is a comprehensive Azure AD / Entra ID assessment platform that combines PowerShell-based session management, Azure CLI parity, and native Graph / ARM API integration. github.com/dmcxblue/ANIMO #infosec #cybersecurity #redteam #pentest #cloud #opensource
github.com
GitHub - dmcxblue/ANIMO: ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments
ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments - dmcxblue/ANIMO
030
r1cksec @r1cksec.bsky.social · 07/08/2026
Interactive CLI Tool that automates Shodan discovery of unsecured robots, ROS nodes, cobots, and ICS. Shipped with 50+ targeted dorks, It can filter, score, and export the results in seconds. github.com/yassinmohame... #infosec #cybersecurity #opensource #osint #shodan #iot
github.com
GitHub - yassinmohamed1111/rodork: Interactive CLI Tool that automates Shodan discovery of unsecured robots, ROS nodes, cobots, and ICS. Shipped with 50+ targeted dorks, It can filter, score, and expo...
Interactive CLI Tool that automates Shodan discovery of unsecured robots, ROS nodes, cobots, and ICS. Shipped with 50+ targeted dorks, It can filter, score, and export the results in seconds. - yas...
030
r1cksec @r1cksec.bsky.social · 06/08/2026
An MCP server that lets an AI agent drive NetExec (nxc) for authorized security testing only. github.com/mpgn/NetExec... #infosec #cybersecurity #pentest #ai
github.com
GitHub - mpgn/NetExec-mcp: NetExec MCP
NetExec MCP. Contribute to mpgn/NetExec-mcp development by creating an account on GitHub.
001
r1cksec @r1cksec.bsky.social · 05/08/2026
New cheatsheets pushed github.com/r1cksec/chea... #infosec #cybersecurity #redteam #pentest #threatintel #malware #dfir #bugbounty #opensource
github.com
GitHub - r1cksec/cheatsheets: Collection of knowledge about information security
Collection of knowledge about information security - r1cksec/cheatsheets
020
r1cksec @r1cksec.bsky.social · 04/08/2026
Windows Provisioning Package (.ppkg) generator. Payload runs as SYSTEM on apply. github.com/init1Securit... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - init1Security/PPKGPacker: Python scripts that helps in the development of PPKG binaries
Python scripts that helps in the development of PPKG binaries - init1Security/PPKGPacker
010
r1cksec @r1cksec.bsky.social · 03/08/2026
A litterbox integration for the Mythic Command and Control Server github.com/Whispergate/... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - Whispergate/Sphinx: A litterbox integration for the Mythic Command and Control Server
A litterbox integration for the Mythic Command and Control Server - Whispergate/Sphinx
010
r1cksec @r1cksec.bsky.social · 31/07/2026
Notes on Windows Component Object Model (COM hijacking, elevation of privilege, DCOM lateral movement, and persistence). Notes were generated by Kimi K3 Swarm may contain inaccuracies. github.com/An0nUD4Y/Off... #infosec #cybersecurity #redteam #pentest #windows
github.com
GitHub - An0nUD4Y/Offensive-COM: Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, ...
Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and per...
010
r1cksec @r1cksec.bsky.social · 29/07/2026
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment. github.com/Kritt-ai/ope... #infosec #cybersecurity #redteam #pentest #ai
github.com
GitHub - Kritt-ai/open-kritt: Orchestrate AI agents to find real vulnerabilities in code.
Orchestrate AI agents to find real vulnerabilities in code. - Kritt-ai/open-kritt
011
r1cksec @r1cksec.bsky.social · 27/07/2026
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. github.com/haxxm0nkey/c... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - haxxm0nkey/credshound: Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. - haxxm0nkey/credshound
041
r1cksec @r1cksec.bsky.social · 26/07/2026
Extract Windows credentials directly from VM memory snapshots and virtual disks github.com/nikaiw/VMkatz #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
042