
bohops
7.6K posts

bohops
@bohops
Red/Purple/Research | Adversary Services @xforce red








🚨 Speaker Announcement – #BSidesPrague2026 🎤 Marco Balzarin Abusing the Ordinary: New COM-Based Windows Attack Vectors Explore Windows COM from an offensive angle—new hunting methods and undocumented techniques for stealthy code execution via legitimate components. #Bsides

Last month, @d_tranman and I gave a talk @MCTTP_Con called "COM to the Darkside" focusing on COM/DCOM cross-session and fileless lateral movement tradecraft. Check out the slides here: github.com/bohops/COM-to-… Recording should be released soon.




I just want to point out: If you use Windows 11, and you think you are being secure by not using a Microsoft account (personal or M365 etc.) then you are likely actually leaving urself exposed to Responser style attacks (or SMB hash theft over the internet/cohersion) if you don't do manual hardening. It's not something I see many talk about, network adjacent attacks are well documented for pen testing but real world incidents we tend to see far more 'they already have creds/shells and then go for kerberoasting etc.' however I want to point it out!






this is what 12 gigs of VRAM built in 2026. a 9 billion parameter model running on a 5 year old RTX 3060 wrote a full space shooter from a single prompt. blank screen on first try. i came back with a bug list and the same model on the same card fixed every issue across 11 files without touching a single line myself. enemies still looked wrong so i pushed another iteration and now the game has pixel art octopi, particle effects, screen shake, projectile physics and a combo system. all running locally on a card that was designed to play fortnite. three iterations. zero cloud. zero API calls. every token generated on hardware sitting under my desk. the model reads its own code, finds what's broken, patches it, validates syntax and restarts the server. i just describe what's wrong and it handles the rest. people are paying monthly subscriptions to type into a browser tab and wait for a server farm to respond. meanwhile a GPU you can find used on ebay is running a full autonomous hermes agent framework with 31 tools, 128K context window and thinking mode generating at 29 tokens per second nonstop. the game still needs work. level upgrades don't trigger and boss fights need tuning. but the fact that i'm iterating on gameplay balance instead of debugging whether the code runs at all tells you where this is headed. every iteration the game gets better on the same hardware. same 12 gigs. same 9 billion parameters. same RTX 3060 from 5 years ago your GPU is not a gaming card anymore. it's a local AI lab that never sends your data anywhere.



