Harpreet Singh

214 posts

Harpreet Singh banner
Harpreet Singh

Harpreet Singh

@TheCyb3rAlpha

Just another Researcher/Wannabe Red Teamer

New Delhi, India Katılım Aralık 2009
272 Takip Edilen121 Takipçiler
Harpreet Singh retweetledi
Rahul
Rahul@sairahul1·
A senior Google engineer just dropped a 424-page doc called Agentic Design Patterns. Every chapter is code-backed and covers the frontier of AI systems: → Prompt chaining, routing, memory → MCP and multi-agent coordination → Guardrails, reasoning, planning This isn't a blog post. It's a curriculum. And it's free. Read it this weekend. That said, I wrote an article on how to build a multi-model AI team in 2026, which was already read by 4 million people. It's a complete guide to agents, models, workflows, and playbook to run your business on autopilot. The article is quoted below.
Rahul tweet media
Rahul@sairahul1

x.com/i/article/2077…

English
32
145
813
117.9K
Harpreet Singh retweetledi
Raytar
Raytar@Raytar·
Andrej Karpathy spent 8 years at OpenAI and Tesla. Last week he put everything he knows into one free 2-hour lecture. People pay $15k for bootcamps that teach half of this. You probably don't have 2 hours right now. Don't lose this in the feed. Watch it. Then read the guide below and build your first loop.
Raytar@Raytar

x.com/i/article/2052…

English
50
353
2.1K
416.1K
Harpreet Singh
Harpreet Singh@TheCyb3rAlpha·
@NinjaParanoid Well, that's what happens when in the name of "Sheekurity", you follow cheat sheets and forget the essence of research behind each engagement. Red teams have always been challenging due to its out-of-the-box approach but some people fail to understand that!
English
0
0
1
1.1K
Chetan Nayak (Brute Ratel C4 Author)
I know a lot of people will hate me for saying this but it has to be said. I get a lot of DMs saying RT is getting harder everyday, traditional loaders dont work anymore, opensource tools tend to crash or get detected instantly. But wasnt that the whole point of Red team? Thats why red teams get paid way more than PT/appsec. RTs are not supposed to be easy, its not just about stealing the first kerberos ticket/Ad Cert and becoming DA. You get paid for the expertise. If you have the same skills as that of general appsec/strategic team, then why would you get paid more? Somehow somewhere someone thought that RTs can be easy money and started providing cheap RTs, providing general PT in the name of RTs, confusing amateur orgs between RT and PT, but infact Redteam was always about research, helping the target organization improve their defense and find flaws in creative ways, or to identify the effects of an adversary. If you have done that and succeeded in improving the security of the org, then it means the next one to improve is you. You cant pray for weak security while doing redteams. Challenges make you better. Staying constant is for the weak.
English
22
56
377
34.7K
Harpreet Singh
Harpreet Singh@TheCyb3rAlpha·
@domchell Especially a nightmare when you realize you missed that one critical screenshot… and now the vulnerable box is long gone 😅
English
0
0
1
155
Dominic Chell 👻
Dominic Chell 👻@domchell·
The one tip I will give to anyone starting out in any pentest / red team role is the one thing after 20 years of it I still never manage to do properly…. Report as you go ✅✅✅ That way you don’t end up spending your Sundays writing reports. Writing a report on a 3.5 month project with minimal notes is brutal 😆❌❌❌
English
29
27
234
25K
Harpreet Singh retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
How would you name your malware so that the level 1 analyst waves it through? I'll start - eicar.exe - keygen.exe - Bloomberg_Excel_Addon.exe - SAP-custom-helper.exe - \SecurityTraining_Oct22\something.exe - \quarantine\inactive-sample-af232.exe
English
195
112
865
0
Harpreet Singh retweetledi
Alisa Esage Шевченко
Alisa Esage Шевченко@alisaesage·
Releasing full 2+hr video of my browser exploitation workshop from VXCON 2024: youtube.com/live/b9OhamkAY… In which I show what goes inside the mind of a skilled hacker while exploiting a highly non-trivial vulnerability in v8, from zero to exploit concept. Especially this workflow requires advanced abstract thinking, thereby emphasize the role of theoretical modeling in attacking hard zeroday research targets, which is a part of why it's fun. @zerodaytraining
YouTube video
YouTube
English
8
241
699
41.1K
Harpreet Singh retweetledi
x86matthew
x86matthew@x86matthew·
DOSVisor - A hypervisor-level emulator for executing 16-bit real-mode DOS programs on Windows github.com/x86matthew/DOS…
Català
3
102
351
31.3K
Harpreet Singh retweetledi
VULNCON
VULNCON@vulncon·
🔐Speaker Release for #VULNCON 2024!🔐 We are thrilled to reveal our next speaker lineup for VULNCON 2024! @TheCyb3rAlpha ! Visit vulncon.in for more details! 🗓️Mark your calendars! 🗓️Date: June 22nd and 23rd,2024 📍Venue: National Science Seminar Complex, IISc, Bengaluru Join us for an enlightening two days where our speakers will share their latest insights and groundbreaking research in cybersecurity! 🎟️ Grab early bird passes till April 25th, book now! :- vulncon.in/register #VULNCON2024 #CyberSecurity #techSpeaker #CyberSecConference #IIScBengaluru #infosec #infosecurity #security #training #conference #research #zeroday #0day #redteam #warfare
VULNCON tweet media
English
0
6
7
810
X
X@TheMsterDoctor1·
🔥Bob the Smuggler" is a tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would compress your binary (EXE/DLL) into 7z/zip file format, then XOR encrypt the archive and then hides inside PNG/GIF image file format (Image Polyglots). The JavaScript embedded within the HTML will download the PNG/GIF file and store it in the cache. Following this, the JavaScript will extract the data embedded in the PNG/GIF, assemble it, perform XOR decryption, and then store it as an in-memory blob. Repo: github.com/TheCyb3rAlpha/…
English
1
24
141
8.1K
Harpreet Singh retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
ulexecve is a userland execve() implementation which helps you execute arbitrary ELF binaries on Linux from userland without the binaries ever having to touch storage. This is useful for red-teaming and anti-forensics purposes. github.com/anvilsecure/ul…
English
0
6
19
3.2K