_Ray

726 posts

_Ray banner
_Ray

_Ray

@_RayRT

Senior Adversarial Engineer Member of EVILCORP\Domain Fathers https://t.co/SIwC7MLXmP https://t.co/WeF9QBYGcQ

가입일 Haziran 2018
892 팔로잉618 팔로워
고정된 트윗
_Ray
_Ray@_RayRT·
Introducing Cyllex - Advanced APT Emulation Framework. cyllex.io I've been working on this for a while, pouring real effort and love into it. Not a quick release, I'm going step by step, building something solid. Some of the current features include: ▸ APT database with real-world campaign emulation ▸ Cross-platform agents via binary patching ▸ Agent, Agentless (WinRM/SSH), and Cloud execution ▸ Direct shell access for real-time interaction ▸ Interactive MITRE ATT&CK detection coverage tracking ▸ Calendar-based campaign scheduling ▸ Webhook notifications (Slack, Teams...) ▸ Robust TTPs: On-Premise (Windows/Linux), Cloud, and Containers I'll be sharing updates as the project evolves. Thank you, and happy new year!
English
8
56
244
15.8K
_Ray 리트윗함
Andrew Oliveau
Andrew Oliveau@AndrewOliveau·
🔥🤖Excited to share a new blog I co-authored with @h4wkst3r and @kulinacs - Automating the Operator: Integrating LLMs into Offensive Security armadin.com/blog-posts/aut… We show how LLMs make offensive work more operationally useful, introduce 2 new MCP servers, and an NTLM relaying Gemini extension POC
English
1
37
112
9.6K
_Ray 리트윗함
Alex Neff
Alex Neff@al3x_n3ff·
Releasing one of my research tools: EVENmonitor🖥️ Inspired by LDAPmonitor, I implemented a monitoring tool for the Windows Event log in pure python. You can just attach it via the network and then filter for specific event IDs or keywords. Available at: github.com/NeffIsBack/EVE…
GIF
English
3
53
202
13.2K
LuemmelSec
LuemmelSec@theluemmel·
This fine dude is doing work for the last 2 weeks :)
LuemmelSec tweet media
English
1
0
25
2.1K
_Ray 리트윗함
Cyllex
Cyllex@CyllexFramework·
Cyllex v0.4.0: 604 TTPs across 7 platforms. Full Azure & GCP cloud coverage, Kubernetes & Docker container testing, 4 SIEM integrations, and 21 APT group profiles in the new APT Codex. Beta is targeting late March / early April. I track progress publicly, you can see exactly where things stand at any point. One last thing: thank you. Building this solo takes time, and knowing people are actually following along makes it worth it. Every subscription, every piece of feedback, every message asking about the beta reminds me why I started this in the first place. Genuinely appreciate the support. #purpleteam #cyllexframework #aptemulation #mitre #attacksimulation
English
1
2
11
1K
Jason Lang
Jason Lang@curi0usJack·
Real imposters don't get imposter syndrome. You're fine.
English
7
18
99
6K
_Ray 리트윗함
InfinityCurve Labs
InfinityCurve Labs@InfinityXCurve·
Havoc Professional Finally Released! 🕸️🕷️ Since our last blog post introducing the Havoc Professional framework and the Kaine-Kit, we've been refining the framework behind the scenes. infinitycurve.org/blog/release
English
0
19
56
8.4K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
WHAT THE FUCK
mRr3b00t tweet media
English
124
35
745
134.4K
_Ray 리트윗함
Andy Gill
Andy Gill@ZephrFish·
Today is the day and I'm sorry it's been so long, and also provisionally delayed by nearly a week. lms.zsec.red launches today with my Malwareless Adversarial Emulation (MAE) course. If you signed up for the waitlist, you should have received an email.
English
9
43
232
36.5K
_Ray
_Ray@_RayRT·
Spent the weekend working on Cyllex and added a Splunk integration for log correlation. Also added detection events for each TTP. There's still a lot of work ahead, but it's starting to look great! I'll keep working on more integrations. Thanks to everyone who's been showing interest and supporting the project! :)
English
0
1
11
774
_Ray 리트윗함
Aurélien Chalot
Aurélien Chalot@Defte_·
Anyone know if Microsoft silently patch the Shadow Creds attack recently ? Looks like a computer object cannot write its own attribute anymore :D
English
11
30
133
43K
_Ray 리트윗함
Romern
Romern@Romerrn·
@Defte_ I just installed a clean version of Server 2022 (20348.169), setup it up as a DC, and tried to create a keycredential. That worked. Than I installed the latest cumulative update (KB5073457) and now it does not work anymore. So it seems to be a recent change.
Romern tweet media
English
2
4
14
2.5K
_Ray 리트윗함
Panos Gkatziroulis 🦄
Panos Gkatziroulis 🦄@ipurple·
🛠️ SharePointDumper: PowerShell SharePoint extraction + auditing tool. ✅Enumerates all SharePoint sites/drives a user can access via Microsoft Graph, recursively downloads files, and logs every Graph + SharePoint HTTP request github.com/zh54321/ShareP…
English
1
49
179
9.8K
_Ray 리트윗함
SpecterOps
SpecterOps@SpecterOps·
WSL2 is a powerful attacker hideout because it runs as a separate Hyper-V VM, and defenders rarely monitor it. Daniel Mayer explains how attackers pivot into WSL2 and what it took to build tooling that works across WSL2 versions. Read more ⤵️ ghst.ly/45fPUma
English
8
174
729
102.6K
_Ray 리트윗함
Lares
Lares@Lares_·
Agentic AI systems are already showing real-world weaknesses. The first OWASP Agentic AI Top 10 highlights where autonomous applications are most exposed. Link: labs.lares.com/owasp-agentic-… ✍️@_RayRT
English
0
2
3
387