Andy Gill @zephrfish.yxz.red · 17/08/2026Thanks @hackglasgow.bsky.social for a truly excellent day, one to remember 040
Reposted by Andy Gillrand0h @akacki.net · 16/08/2026Idk how @zephrfish.yxz.red makes me feel so pretty. 2121
Reposted by Andy Gillrand0h @akacki.net · 11/08/2026When I asked @zephrfish.yxz.red how our brand of slide stupidity would play in Glasgow he responded “well enough”. So this ought to be interesting. 😂 292
Reposted by Andy GillHack Glasgow @hackglasgow.bsky.social · 28/07/2026We're delighted that ZephrSec is a sponsor for Hack Glasgow 2026! Founder @zephrfish.yxz.red is an experienced red teamer, author, regular attendee (and previous speaker) at our Hack Thursday meetup, and keen supporter of the cyber security community, especially in his home town of Glasgow. 131
Reposted by Andy GillHack Glasgow @hackglasgow.bsky.social · 02/07/2026This year's event features @gabsmashh.bsky.social, Liam Follin, Scott McCracken, @zephrfish.yxz.red, Alex Close, Marie Dubremetz, Ken Munro, @akacki.net, Aaron Kelly, @gl4cier.bsky.social, Chris Bore, Michael Reimsbach, @rxerium.com, Ehren Osborne, [...]pretalx.hackglasgow.live 122
Reposted by Andy GillHack Glasgow @hackglasgow.bsky.social · 18/06/2026Happy Hack Thursday, and happy Hack Glasgow speaker announcement! We're excited to announce that @zephrfish.yxz.red and Alex Close will be presenting 'The Hunted Becomes the Hunter: Catching Red Teamers and Pentesters and Spotting Adversarial Patterns' at Hack Glasgow! 173
Andy Gill @zephrfish.yxz.red · 13/06/2026It’s @bsidesleeds.bsky.social today and ZephrSec sponsoring. Come along to my talk talk at 11.40 in Track 1 all about blending into environments using defensive tools and understanding. Our 10% off coupon is also still live: LTR101-10Y lms.zsec.redlms.zsec.redRed Team Training: MAE — Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 021
Reposted by Andy GillBSides Leeds @bsidesleeds.bsky.social · 10/06/2026As we get ever closer to Saturday and the conference day, we wanted to put out another huge thank you to all of our fantastic sponsors ❤️ Genuinely, BSides Leeds would not be able to run without your support. We're so grateful that you were keen to be involved and help us make this happen! 184
Reposted by Andy GillBSides Leeds @bsidesleeds.bsky.social · 10/06/2026Torq @semgrep.com @pentestpartners.bsky.social ZephrSec - @zephrfish.yxz.red 122
Andy Gill @zephrfish.yxz.red · 01/06/2026Always happens when I take time off I end up writing things, here's the latest post blog.zsec.uk/baselining-w... all about learning the baselines of Windows, it doesn't cover everything and anything but I've spun up a lab with observability and tried to write some detections baselining. Enjoy! 031
Reposted by Andy GillBSides Leeds @bsidesleeds.bsky.social · 24/05/2026🕹️ SPEAKER ANNOUNCEMENT 🎮️ We're excited to have @zephrfish.yxz.red presenting his talk 'Archaic Creativity: Pulling At Infinite Threads'. Catch Andy's talk on Track 1, and keep an eye on our website and socials for the full schedule release! #BSidesLeeds #SpeakerAnnouncement 064
Andy Gill @zephrfish.yxz.red · 09/05/2026It’s been 10 years since I published my first book(LTR101), so to celebrate I’m giving 10% off my red team course, Malwareless Adversarial Emulation (MAE). Check it out here: lms.zsec.red Discount code: LTR101-10Y Valid until the end of August 2026.lms.zsec.redRed Team Training: MAE — Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 000
Reposted by Andy GillHack Glasgow @hackglasgow.bsky.social · 05/05/2026It's clear to see the amount of work that's gone into it — please do take a look: lms.zsec.red #HackGlasgow2026 #SponsorAnnouncementlms.zsec.redRed Team Training: MAE — Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 021
Reposted by Andy GillHack Glasgow @hackglasgow.bsky.social · 05/05/2026We're delighted to announce ZephrSec as a sponsor for Hack Glasgow 2026! Founder @zephrfish.yxz.red is an experienced red teamer, author, regular attendee (and previous speaker) at our Hack Thursday meetup, and keen supporter of the cyber security community, especially in his home town of Glasgow. 153
Reposted by Andy GillBSides Leeds @bsidesleeds.bsky.social · 15/04/2026Welcome onboard ZephrSec! 🎉 ZephrSec is all about giving back to the community, helping others grow through hands-on training, adversarial emulation, and real-world security insights. Levelling up the next generation of defenders & attackers 🚀 lms.zsec.red @zephrfish.yxz.red 061
Andy Gill @zephrfish.yxz.red · 04/04/2026This is what happens when I take time off, I actually write silly length blog posts and deep dive things blog.zsec.uk/bullyingllms/ the post dives into a MCP pipeline I've put together for autonomous 0day hunts.blog.zsec.ukAutonomous Vulnerability Hunting with MCPAlt title: Bullying LLMs into submission to find 0days at scale 031
Reposted by Andy GillSteelCon @steelcon.info · 25/03/2026You've got till Friday 3rd to submit your talks and workshops. We've got plenty of talks but could do with a few more workshops, so if you've got an idea, but aren't sure, submit it anyway and let us decide forms.gle/hLXt1dibQrA6... 054
Andy Gill @zephrfish.yxz.red · 16/03/2026It's 4 weeks to the date since I launched ZephrSec Ltd LMS and Malwareless Adversarial Emulation(MAE), here's a blog post about a lot of the challenges, lessons learnt and general chaos of building and running your own platform and all the fun that follows building blog.zsec.uk/roll-your-ow...blog.zsec.ukRoll Your Own... LMSPeople say don't roll your own crypto but nobody ever warns you not to roll your own LMS (when you have minimal dev experience). 023
Reposted by Andy GillSteelCon @steelcon.info · 24/02/2026With Easter coming up quick it is time for a date announcement. 1 March - CFP and call for crew opens 1 April - Pre talk announcement tickets 3 April CFP and CFC closes ~ 20 April speakers confirmed ~ 24 April main ticket drop Links and stuff coming closer to the dates. 1138
Reposted by Andy GillSteelCon @steelcon.info · 04/03/2026Our first fully committed sponsor is @zephrfish.yxz.red. Long time supporter as a speaker and now a sponsor as well. Andy would like everyone to know about his Malwareless Adversarial Emulation training course lms.zsec.red We may be biased, but we reckon it is top quality stuff.lms.zsec.redRed Team Training: MAE — Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 085
Andy Gill @zephrfish.yxz.red · 17/02/2026Since launching MAE over the weekend I’ve had a lot of great feedback from the community and I want to say how thankful I am for everyone’s support. One of the requests I had was for multi language support on subtitles, so I went ahead and added it to the platform. go check it out lms.zsec.red 032
Reposted by Andy Gillrand0h @akacki.net · 14/02/2026I love watching my friends create awesome stuff. @zephrfish.yxz.red made some artisan, farm to table, shell to terminal red team training for you. lms.zsec.redlms.zsec.redMAE - Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 084
Reposted by Andy GillRey Bango @reybango.bsky.social · 14/02/2026I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable. The course is at lms.zsec.red 122
Andy Gill @zephrfish.yxz.red · 14/02/2026Today’s the day, finally got around to publishing my red team course, with video, written and self spin up labs. lms.zsec.redlms.zsec.redMAE - Malwareless Adversary EmulationAdvanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences. 045
Andy Gill @zephrfish.yxz.red · 04/01/2026Turns out I’m not very active on here or Twitter anymore even though over the years I’ve accumulated 19k followers on Twitter 😬 120
Andy Gill @zephrfish.yxz.red · 13/09/2025Made a thing, mucking about with python and a LDAP browser concept to ingest straight into BloodHound but also just a nice alternative to ADExplorer with fewer LDAP queries, simple LDAP browser using PyQt as a GUI and neo4j-driver to ingest into BH. github.com/ZephrFish/py... #bloodhound #redteamgithub.comGitHub - ZephrFish/pyLDAPGui: Python based GUI for browsing LDAPPython based GUI for browsing LDAP. Contribute to ZephrFish/pyLDAPGui development by creating an account on GitHub. 081
Andy Gill @zephrfish.yxz.red · 16/06/2025Couple updates: Course Trailer and Sign Up: mae.zsec.red GoClipC2 - blog.zsec.uk/clippy-goes-...mae.zsec.redMalwareless Adversarial Emulation | Living off the Knowledge 001
Reposted by Andy GillAndy Gill @zephrfish.yxz.red · 27/04/2025Weekends are for random projects Here is a blog post all around Kerberos errors and a bonus interactive app built in collaboration with @thecontractor.io Errorism Index for Kerberos blog.zsec.uk/common-tool-... kerberos.errorism.ioblog.zsec.ukCommon Tool Errors - KerberosSo you are performing your favourite kerberos attacks, such as pass the ticket, Public Key Cryptography for Initial Authentication (PKINIT), Shadow Credentials or Active Directory Certificate Services... 042
Andy Gill @zephrfish.yxz.red · 27/04/2025Weekends are for random projects Here is a blog post all around Kerberos errors and a bonus interactive app built in collaboration with @thecontractor.io Errorism Index for Kerberos blog.zsec.uk/common-tool-... kerberos.errorism.ioblog.zsec.ukCommon Tool Errors - KerberosSo you are performing your favourite kerberos attacks, such as pass the ticket, Public Key Cryptography for Initial Authentication (PKINIT), Shadow Credentials or Active Directory Certificate Services... 042
Reposted by Andy GillSteelCon @steelcon.info · 24/04/2025First round of talk emails have just gone out. We had over 40 submissions for 18 slots so unfortunately have had to reject over half of them. If you haven't had an email yet, please hang on, more will be sent out shortly as we finalise other things. 055
Reposted by Andy GillMark Carney @mark-carney.bsky.social · 22/03/2025Elbows up, Canada. 14745202213264
Andy Gill @zephrfish.yxz.red · 23/03/2025Want a nice Sunday hack? The function that android has had for years but a nice to have on iPhone, estimated minutes to charge. 100
Andy Gill @zephrfish.yxz.red · 12/03/2025Sign it nerds you.38degrees.org.uk/petitions/ke...you.38degrees.org.ukKeep our Apple data encryptedIt is reported that the Home Office has ordered Apple to build a backdoor into its encrypted services so that they can get hold of content that any Apple user has upload to the cloud. Encryption keeps... 001
Reposted by Andy GillAndy Gill @zephrfish.yxz.red · 09/03/2025Here's RepoMan, a proof of concept surrounding git commit poisoning. The blog post dives a little deeper into how it all works and the rationale behind it. blog.zsec.uk/navigating-a... github.com/ZephrFish/Re...blog.zsec.ukNavigating AI 🤝 Fighting SkynetUsing AI can be a great tool for adversarial engineering. This was just a bit of fun to see if it was possible todo and to learn more about automation but also proving you cannot trust git commit hist... 363
Andy Gill @zephrfish.yxz.red · 09/03/2025Here's RepoMan, a proof of concept surrounding git commit poisoning. The blog post dives a little deeper into how it all works and the rationale behind it. blog.zsec.uk/navigating-a... github.com/ZephrFish/Re...blog.zsec.ukNavigating AI 🤝 Fighting SkynetUsing AI can be a great tool for adversarial engineering. This was just a bit of fun to see if it was possible todo and to learn more about automation but also proving you cannot trust git commit hist... 363
Andy Gill @zephrfish.yxz.red · 02/03/2025Finally got around to finishing the series here's part 3 of my NUC stack series blog.zsec.uk/homelab-clus...blog.zsec.uk(Re)Building the Ultimate Homelab NUC Cluster - Part 3Set up a Docker-based homelab with automation, monitoring & media tools like Plex, Sonarr & Portainer for easy management & scalability. 3162
Andy Gill @zephrfish.yxz.red · 02/03/2025Better to be a warrior in a garden than a gardener in a war 000
Andy Gill @zephrfish.yxz.red · 01/03/2025Following up on my talk, I mentioned if you wanted to get my books for free, you could probably find them on Google; well, there's no need. I've set the bundle on leanpub for the ebook to $0.00, aka free, so you can get a copy of both LTR101 and LTR102! leanpub.com/b/LearningTh... #SecuriTay2025 021
Andy Gill @zephrfish.yxz.red · 27/02/2025Got a busy few months ahead but I will eventually finish the NUC series! If you missed the first two parts they're here: blog.zsec.uk/homelab-clus... blog.zsec.uk/homelab-clus...blog.zsec.uk(Re)Building the Ultimate Homelab NUC Cluster - Part 1Explore my blog series on building a NUC cluster with Proxmox! Learn about connecting hosts, setting up tools, and avoiding pitfalls from my own build mistakes. Perfect for anyone keen on creating a h... 090
Andy Gill @zephrfish.yxz.red · 27/02/2025Slides are done for SecuriTay and talk will be tomorrow afternoon on track 1, come along and listen to "Think Like an Adversary" designed to show both sides of the coin what a real world attack looks like and where the detection opportunities exist 041
Andy Gill @zephrfish.yxz.red · 27/02/2025As I slowly ease back into using socials I think I'm going to fully move off of Twitter and keep my account locked but rather post on here. If you followed me from Twitter hello again! But if you're new here, welcome! I post a mix of photography, hacks, rants and everything in between 🤘🏻 3180
Andy Gill @zephrfish.yxz.red · 16/02/202512 years ago I went to see You Me At Six, and in 5 weeks time I'll see them again at their final gig in Glasgow🥲 020
Andy Gill @zephrfish.yxz.red · 02/02/2025I’m a fucking morning person on the weekends but not the week, why brain 040