Keanu Nys

107 posts

Keanu Nys banner
Keanu Nys

Keanu Nys

@RedByte1337

Offensive Security Lead @ Spotit. Creator of GraphSpy

Belgium Beigetreten Ağustos 2014
78 Folgt1.1K Follower
Angehefteter Tweet
Keanu Nys
Keanu Nys@RedByte1337·
🚀I'm finally releasing GraphSpy to the public!🕵️ A powerful offensive security tool focused on making initial access and post-compromise enumeration in Microsoft Entra and M365 much more convenient during penetration tests and red team assessments! github.com/RedByte1337/Gr…
English
3
136
378
34.7K
Mike Manrod
Mike Manrod@CroodSolutions·
IMHO, this is a must-watch video, showcasing why defending against account takeover is such a struggle. Outstanding episode by @_JohnHammond and @RedByte1337 - great research Keanu!! At the minimum, all red, SOC teams, and detection engineers, IMHO, should watch this.
John Hammond@_JohnHammond

GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE

English
1
3
48
4.6K
Keanu Nys
Keanu Nys@RedByte1337·
I recently sat down with @_JohnHammond to record a video about GraphSpy! 😁 We went over the most powerful features GraphSpy has to offer, and even showcased some of the new features that were added lately. This video is now live on his YouTube channel, so go check it out! 😉
John Hammond@_JohnHammond

GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE

English
2
7
42
8.8K
Kuba Gretzky
Kuba Gretzky@mrgretzky·
What? How am I going to set up a @ThinkstCanary CSS Canarytoken to protect my tenant from those pesky Evilginx phishing attacks, now? 😐
Kuba Gretzky tweet media
English
3
3
55
6.2K
Keanu Nys
Keanu Nys@RedByte1337·
Maximum 16-character password "for security reasons". 🤔 And what I find more surprising is the fact that the "<" character is not permitted either... Is this some poor attempt at preventing XSS? That would mean the password is displayed in cleartext somewhere on a web page...🤨
Keanu Nys tweet media
English
0
1
5
342
Keanu Nys
Keanu Nys@RedByte1337·
I will be teaching the advanced version of the Attacking & Defending Azure Cloud bootcamp once again in February with @AlteredSecurity! Live, hands-on Azure red team training with realistic labs to sharpen both your Offensive and Defensive skills! 🔥 🔗 alteredsecurity.com/carte-bootcamp
English
0
2
8
574
Keanu Nys
Keanu Nys@RedByte1337·
@mrgretzky Haha, thanks Kuba. Small stuff compared to what you achieved with Evilginx ofc 😜
English
1
0
1
144
Keanu Nys
Keanu Nys@RedByte1337·
GraphSpy just hit 1000 ⭐ on GitHub! What started as a personal side project is now used by pentesters around the world. Never imagined this as my first project, especially not in under 2 years. 🤯 I silently pushed v1.6 right before the holidays with powerful new features 😉
Keanu Nys tweet media
English
4
5
32
2.7K
Keanu Nys
Keanu Nys@RedByte1337·
Wow, this almost passed by without me noticing👀 This is not how I envisioned GraphSpy to be covered in a @_JohnHammond video, but then again, it was only a matter of time before malicious actors used it. You just hope it is used for more good than bad when creating these tools.
John Hammond@_JohnHammond

Uncovered screen recordings from threat actors! 👀 Real footage of cybercriminals using anti-detect browsers and infostealer malware logs for session hijacking, and another using GraphSpy to read their Entra ID victim's emails in Outlook! 💀 Video: youtu.be/vX7JcpRqbEk

English
0
1
9
1.6K
Keanu Nys
Keanu Nys@RedByte1337·
@_dirkjan @Thomasbyrne__ For now 😉 I hope for a bit longer, but we'll see. In theory, the October deadline has lapsed, so I guess you did indeed win from that perspective 😅
English
0
0
1
151
Dirk-jan
Dirk-jan@_dirkjan·
It appears the end is near(er) for the Azure AD Graph API with usage of the API now being blocked in one of my tenants with the AAD PowerShell module client ID. Found this out when trying to demo roadrecon 😬. Time to prioritize merging the MS Graph PR from @Thomasbyrne__
English
5
24
135
13.8K
Keanu Nys
Keanu Nys@RedByte1337·
@_dirkjan @Thomasbyrne__ Whether the AAD Graph API would continue to work after the final deadline of October 2025 😅 Your guess was that it would still work for first-party client IDs. 🙈
English
1
0
1
149
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
DefCon published the videos from this years talks on YouTube two weeks ago. Which ones should I watch?
English
27
23
391
46.9K
Keanu Nys
Keanu Nys@RedByte1337·
@_dirkjan It should have been 10.0 from the start. "Attack Complexity=High" did really not make any sense!
English
0
0
1
165
Mehmet Ergene 🔸
Mehmet Ergene 🔸@Cyb3rMonk·
Did Microsoft just disable custom font-face in company branding CSS after the DEFCON talk?👀 @RedByte1337 I don't have an older CSS template to compare.
Mehmet Ergene 🔸 tweet media
English
2
0
14
6.4K
Keanu Nys
Keanu Nys@RedByte1337·
@TEMP43487580 Nice findings! Don't let the responses from MSRC discourage you, this is very interesting stuff!
English
1
0
5
1.5K
%TEMP%
%TEMP%@TEMP43487580·
I just started a new blog, and this is my first post. I took a bit of PTO, so this is a little record of some fun I had playing around with Intune during that time. It's about enrollment restriction bypass😄 temp43487580.github.io/intune/bypass-…
English
14
69
245
48.6K