Beau Bullock
4.2K posts

Beau Bullock
@dafthack
Hacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH
Florida, USA Katılım Ocak 2013
661 Takip Edilen18.4K Takipçiler

@_subTee Thanks so much for the kind words Casey! I hope you are doing well man!
English
Beau Bullock retweetledi

Next week at @WWHackinFest I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀

English
Beau Bullock retweetledi
Beau Bullock retweetledi
Beau Bullock retweetledi

“Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models”
One day we might be hiring literature majors in cybersecurity.
arxiv.org/abs/2511.15304
English
Beau Bullock retweetledi

Join @dafthack for his precon training class, "Breaching the Cloud," at Wild West Hackin' Fest - Mile High 2026!
Don't ya go missin' it, grab yer tickets to the con today!
wildwesthackinfest.com/wild-west-hack…

English
Beau Bullock retweetledi

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English

Want to learn how modern attackers hack cloud infrastructure like Azure and AWS? In two weeks (9/23 & 9/24) I'm teaching Breaching the Cloud live and fully remote.
Register here:
antisyphontraining.com/product/breach…
@Antisy_Training
English
Beau Bullock retweetledi

Two opportunities to take my Breaching the Cloud course live are coming up soon. If you want to learn how to hack cloud environments like Azure and AWS this is the course for you.
Sep. 23 & 24 - Fully remote and live
Oct. 7 & 8 - In-person only at @WWHackinFest
Register here:
antisyphontraining.com/course/breachi…

English

@Badgerops @stokfredrik Ha! Yeah that was quite the surprise! Awesome to meet you too! 🤘
English

Just thinking about that time I ran into @stokfredrik and @dafthack at a random metal shop in Stockholm and had no idea who Stök was. Was good to meet both of y’all, and discover the cool things you’ve been working on!
English
Beau Bullock retweetledi

Check out my new blog on nested app authentication and brokered authentication.
SpecterOps@SpecterOps
Why should Microsoft's Nested App Authentication (NAA) should be on your security team's radar? @Icemoonhsv breaks down NAA and shows how attackers can pivot between Azure resources using brokered authentication. ghst.ly/45h2Zw3
English
Beau Bullock retweetledi

FIDO downgrades are still possible, in reverse proxy phishing attacks, if you manage to convince the server that your device does not support strong MFA. 🪝🐟
Research from @proofpoint:
proofpoint.com/us/blog/threat…
English
Beau Bullock retweetledi

New downgrade attack can bypass FIDO auth in Microsoft Entra ID - @billtoulas
bleepingcomputer.com/news/security/…
bleepingcomputer.com/news/security/…
English
Beau Bullock retweetledi

I've been using Microsoft Teams wrong this entire time
Browntable@Browntable_Ent
THIS CAN'T BE A REAL MOVIE
English
Beau Bullock retweetledi

🚨 Microsoft just warned: CVE-2025-53786 lets hackers silently escalate privileges from on-prem Exchange to the cloud.
No logs. No easy traces.
Your hybrid setup could be a silent breach vector.
Full details + fixes → thehackernews.com/2025/08/micros…
English
Beau Bullock retweetledi

we got a persistent 0click on ChatGPT by sharing a doc
that allowed us to exfiltrate sensitive data and creds from your connectors (google drive, sharepoint, ..) + chat history
+ future conversations
it gets worse. we deploy a memory implant
#DEFCON #BHUSA @tamirishaysh
English
Beau Bullock retweetledi

During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs.
github.com/olafhartong/Ba…
Slides available here:
github.com/olafhartong/Pr…
English
Beau Bullock retweetledi

I pushed updates to SCCMHunter as part of my Arsenal demo at #BHUSA today! New features include a relay module for TAKEOVER-5 and a community contribution to coerce client push from a *nix host for ELEVATE-2. github.com/garrettfoster1….
English
Beau Bullock retweetledi

**NEW RELEASE**
Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource
10 essential offensive tool references, available as PDFs or blog posts. Download all or individual sheets.
Thanks again to all our contributors!
Check it out: blackhillsinfosec.com/offensive-tool…

English



