Keanu Nys

112 posts

Keanu Nys banner
Keanu Nys

Keanu Nys

@RedByte1337

Offensive Security Lead @ Spotit. Creator of GraphSpy

Belgium Katılım Ağustos 2014
79 Takip Edilen1.2K Takipçiler
Sabitlenmiş Tweet
Keanu Nys
Keanu Nys@RedByte1337·
🚀I'm finally releasing GraphSpy to the public!🕵️ A powerful offensive security tool focused on making initial access and post-compromise enumeration in Microsoft Entra and M365 much more convenient during penetration tests and red team assessments! github.com/RedByte1337/Gr…
English
3
136
380
34.8K
Keanu Nys
Keanu Nys@RedByte1337·
Just shipped GraphSpy v1.7.0 ✨ Mostly under-the-hood work this time with major refactoring to speed up future development ⚙️ Huge shoutout to n3rada for leading the effort! More exciting features coming soon 🚀 github.com/RedByte1337/Gr…
English
1
12
40
2.8K
Fabian Bader
Fabian Bader@fabian_bader·
📢 You already know FOCI, BroCI, and all the OAuth2.0 flows? But do you already know the secret token providers of Entra ID? In my latest research post I explore how you can, hidden from the Defenders, request new access token. cloudbrothers.info/en/avoid-entra… #EntraID #DefenderXDR
English
3
60
196
44.5K
Keanu Nys retweetledi
Keanu Nys retweetledi
Kuba Gretzky
Kuba Gretzky@mrgretzky·
It was an honour to share what I've been working on on the stream! It was a blast! 🪝🐟 The demo gods were thankfully kind to me. 🙏 P.S. To anyone copying the session cookies character-by-character from the video feed - all the sessions have been invalidated. 🥲
Stephen Sims@Steph3nSims

Big thanks to @mrgretzky for a great stream on the latest in MFA bypass attacks with Evilginx and Phishlets 2.0! Each time web developers come up with new ways to secure things, Kuba is right there to find a workaround! You can watch the recording here: youtube.com/live/eeauoOYUw…

English
3
9
47
4.2K
Mike Manrod
Mike Manrod@CroodSolutions·
IMHO, this is a must-watch video, showcasing why defending against account takeover is such a struggle. Outstanding episode by @_JohnHammond and @RedByte1337 - great research Keanu!! At the minimum, all red, SOC teams, and detection engineers, IMHO, should watch this.
John Hammond@_JohnHammond

GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE

English
1
3
48
4.6K
Keanu Nys
Keanu Nys@RedByte1337·
I recently sat down with @_JohnHammond to record a video about GraphSpy! 😁 We went over the most powerful features GraphSpy has to offer, and even showcased some of the new features that were added lately. This video is now live on his YouTube channel, so go check it out! 😉
John Hammond@_JohnHammond

GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE

English
2
9
44
9.2K
Kuba Gretzky
Kuba Gretzky@mrgretzky·
What? How am I going to set up a @ThinkstCanary CSS Canarytoken to protect my tenant from those pesky Evilginx phishing attacks, now? 😐
Kuba Gretzky tweet media
English
3
3
56
6.2K
Keanu Nys
Keanu Nys@RedByte1337·
Maximum 16-character password "for security reasons". 🤔 And what I find more surprising is the fact that the "<" character is not permitted either... Is this some poor attempt at preventing XSS? That would mean the password is displayed in cleartext somewhere on a web page...🤨
Keanu Nys tweet media
English
0
1
5
378
Keanu Nys
Keanu Nys@RedByte1337·
I will be teaching the advanced version of the Attacking & Defending Azure Cloud bootcamp once again in February with @AlteredSecurity! Live, hands-on Azure red team training with realistic labs to sharpen both your Offensive and Defensive skills! 🔥 🔗 alteredsecurity.com/carte-bootcamp
English
0
2
9
606
Keanu Nys
Keanu Nys@RedByte1337·
@mrgretzky Haha, thanks Kuba. Small stuff compared to what you achieved with Evilginx ofc 😜
English
1
0
1
151
Keanu Nys
Keanu Nys@RedByte1337·
GraphSpy just hit 1000 ⭐ on GitHub! What started as a personal side project is now used by pentesters around the world. Never imagined this as my first project, especially not in under 2 years. 🤯 I silently pushed v1.6 right before the holidays with powerful new features 😉
Keanu Nys tweet media
English
4
5
32
2.8K
Keanu Nys
Keanu Nys@RedByte1337·
Wow, this almost passed by without me noticing👀 This is not how I envisioned GraphSpy to be covered in a @_JohnHammond video, but then again, it was only a matter of time before malicious actors used it. You just hope it is used for more good than bad when creating these tools.
John Hammond@_JohnHammond

Uncovered screen recordings from threat actors! 👀 Real footage of cybercriminals using anti-detect browsers and infostealer malware logs for session hijacking, and another using GraphSpy to read their Entra ID victim's emails in Outlook! 💀 Video: youtu.be/vX7JcpRqbEk

English
0
1
9
1.7K
Keanu Nys
Keanu Nys@RedByte1337·
@_dirkjan @Thomasbyrne__ For now 😉 I hope for a bit longer, but we'll see. In theory, the October deadline has lapsed, so I guess you did indeed win from that perspective 😅
English
0
0
1
153
Dirk-jan
Dirk-jan@_dirkjan·
It appears the end is near(er) for the Azure AD Graph API with usage of the API now being blocked in one of my tenants with the AAD PowerShell module client ID. Found this out when trying to demo roadrecon 😬. Time to prioritize merging the MS Graph PR from @Thomasbyrne__
English
5
24
135
13.8K
Keanu Nys
Keanu Nys@RedByte1337·
@_dirkjan @Thomasbyrne__ Whether the AAD Graph API would continue to work after the final deadline of October 2025 😅 Your guess was that it would still work for first-party client IDs. 🙈
English
1
0
1
151
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
DefCon published the videos from this years talks on YouTube two weeks ago. Which ones should I watch?
English
27
22
389
46.9K