Mayfly

574 posts

Mayfly banner
Mayfly

Mayfly

@M4yFly

Former Dev and DevOps| Pentester and red teamer at orange cyberdefense | OSCE³| Tweet are my own| discord: m4yfly

Katılım Kasım 2017
787 Takip Edilen7.3K Takipçiler
Mayfly retweetledi
TrustedSec
TrustedSec@TrustedSec·
Who knew a really long string could make an Entra ID login disappear from the logs entirely? In our #blog, @nyxgeek breaks down how overflowing #Azure's sign-in logging mechanism allowed access tokens to be issued without a single log entry. Read it now! hubs.la/Q047xTVc0
English
3
73
272
70.4K
Mayfly retweetledi
Bad Sector Labs
Bad Sector Labs@badsectorlabs·
🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)
English
3
20
77
6.6K
Mayfly retweetledi
John Hammond
John Hammond@_JohnHammond·
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE
YouTube video
YouTube
John Hammond tweet media
English
6
67
395
52K
Mayfly
Mayfly@M4yFly·
@vladimircicovic you have to do that for python but this should already be done if you installed goad before, but you have to do that for ansible-galaxy too ! (cause some dependencies were added on ansible)
English
0
0
0
51
Mayfly
Mayfly@M4yFly·
🔥🐉 New GOAD Lab: DRACARYS I’ve just released a new free lab environment on GOAD: DRACARYS. The challenge includes 3 VMs and the objective is simple: Start with no authentication and work your way up to Domain Admin. Have fun exploiting it! 🔥🐉 mayfly277.github.io/posts/Dracarys…
English
9
98
290
16.2K
Mayfly retweetledi
𝘾𝙝𝙧𝙞𝙨𝙩𝙤𝙥𝙝𝙚 𝘽𝙤𝙪𝙩𝙧𝙮
🚨 YGG — C’est terminé. #YGGdown Les serveurs auraient été vidés, puis détruits. Dans un article publié sur yggleak.top/fr, Grolum détaille la compromission totale de l’infrastructure (code, bases, configs, logs), sur fond de crise autour du “Turbo Mode” et de la monétisation. YGGLeak affirme aussi que le catalogue de torrents aurait été préservé avec l’aide du projet U2P, et annonce : - un tracker temporaire : ygg[.]gratis - des “nouveaux trackers” et une migration via ygg[.]gratis
𝘾𝙝𝙧𝙞𝙨𝙩𝙤𝙥𝙝𝙚 𝘽𝙤𝙪𝙩𝙧𝙮 tweet media
Français
103
244
1.7K
398.3K
Mayfly retweetledi
Panos Gkatziroulis 🦄
Panos Gkatziroulis 🦄@ipurple·
Stuck Without Coercion options? Why not just Coerce MDE? @Sniffler/stuck-without-coercion-options-why-not-just-coerce-mde-aecc23b43b66" target="_blank" rel="nofollow noopener">medium.com/@Sniffler/stuc…
English
2
29
107
9.9K
Mayfly retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
Forgot to post it, but the recording of my Black Hat talk was released last week. If you're interested in all the hybrid AD attack surface you never knew about, give it a watch: youtu.be/rzfAutv6sB8?si…
YouTube video
YouTube
English
2
109
378
28.1K
Mayfly
Mayfly@M4yFly·
@SpecterOps @rbnroot Nice! I already built a similar tool, but CLI-only and with fewer options. Great work, very usefull in red team - thank you! 👏
English
0
0
6
1.2K
Mayfly retweetledi
SpecterOps
SpecterOps@SpecterOps·
Every Entra ID assessment ends here: “How do I get a token without triggering Conditional Access controls?” 🤔 @rbnroot built CAPSlock, an offline ROADrecon-based Conditional Access engine that simulates sign-ins & flags gaps without touching the tenant. ghst.ly/4aKIk64
English
3
89
279
28.4K
Mayfly retweetledi
Atsika
Atsika@_atsika·
🥳 ProxyBlob V2 is now available 🎉 As promised, here is the new version of ProxyBlob, boosted with aznet. Az-what 🤔? This version introduces a new Go module called aznet that allows you to use Azure storage services (not just blobs 😏) as a direct replacement for net.Conn! 🏎️github.com/Atsika/aznet 🌐github.com/quarkslab/prox… Complete documentation is available in the aznet repo to understand how it works 📚
Atsika tweet media
English
1
29
68
5.3K
Mayfly retweetledi
n00py
n00py@n00py1·
NTLM reflection attacks can be used to compromise Active Directory domains even with SMB signing if systems aren’t fully patched depthsecurity.com/blog/using-ntl…
English
4
118
373
23.8K
Mayfly
Mayfly@M4yFly·
@mariuszbit Congratulations, Marius! Great hire by Outflank—I’m sure you’re going to absolutely rock it there. They’re lucky to have you!
English
1
0
1
295
mgeeky | Mariusz Banach
mgeeky | Mariusz Banach@mariuszbit·
☢️ 2026 started with a bang! The project I've been building for the last three years - an Initial Access framework letting us weaponize 100+ file formats - is joining Outflank's OST & I'm joining too!😍 🔥 Same mission, now with joint R&D to ship even more high-quality RT tools!
Outflank@OutflankNL

📢 Big News! @mariuszbit is joining Outflank! He ticks all the boxes: Experienced #offsec researcher ✓ Respected name in red teaming ✓ Built RMF tooling for initial access ✓ His work is coming to OST✓ The red hoodie fits perfectly ✓ Welcome Mariusz! outflank.nl/blog/2026/01/2…

English
13
9
83
10.1K
Mayfly retweetledi
Synacktiv
Synacktiv@Synacktiv·
🚨 RCE in #Livewire (CVE-2025-54068)! Our specialists uncovered a critical flaw allowing remote code execution without the APP_KEY, exploiting Livewire’s hydration mechanism + PHP’s loose typing. 🔗 Patch now! (v3.6.4+) synacktiv.com/en/publication…
English
2
62
168
47.6K
Mayfly
Mayfly@M4yFly·
🚀 Introducing MoxPack: A template builder for Proxmox using Packer. Generate Windows & Linux VM templates with cloud-init support and sysprep. Ideal for lab automation and infra-as-code. github.com/Orange-Cyberde…
English
0
31
129
11.4K
Mayfly retweetledi
mpgn
mpgn@mpgn_x64·
Thrilled to share that the Star Wars NetExec lab I made for @_leHACK_ was fully automated by @LadhaAleem on Ludus/VWmare/VirtualBox🔥 Awesome lab with 2AD (rebels&empire), certificats, MSSQL trust, pre2k, and ofc gMSA 👾 Can you find the spy ? GitHub ➡️ github.com/Pennyw0rth/Net…
English
3
78
295
16.4K