Panos Gkatziroulis 🦄

14.8K posts

Panos Gkatziroulis 🦄 banner
Panos Gkatziroulis 🦄

Panos Gkatziroulis 🦄

@ipurple

Red/Purple Teamer | Blogger | Ex-Director @pentestlabltd | Mod @ https://t.co/1nzjl9KpSH | https://t.co/mIM1GA1mN4

Internet Katılım Ocak 2012
824 Takip Edilen26.6K Takipçiler
Panos Gkatziroulis 🦄 retweetledi
Threat Hunting Labs
Threat Hunting Labs@ThruntingLabs·
macOS labs in THL just got a real upgrade. We’ve released guided macOS investigation help for supported labs, giving learners better structure while they work through unfamiliar telemetry. This includes: - macOS telemetry orientation - question-level investigation guidance - field and artifact explanations - common mistake callouts - methodology-focused debriefs - better support for learning the workflow, not memorizing answers macOS intrusion investigations need their own muscle memory. You need to understand where process activity shows up, how shell behavior looks, where collection and staging evidence tends to appear, and how to validate the sequence without assuming Windows patterns apply. That is what this update is designed to support. Tomorrow, a new investigation will make that much more concrete! Check out our labs -> threathuntinglabs.com/threat-hunting
Threat Hunting Labs tweet media
English
0
11
57
25.8K
Panos Gkatziroulis 🦄
The main reason X changed its algorithm to reduce visibility on posts containing external links (blogs, YouTube videos, etc.) is to push users toward writing more articles and long‑form posts, giving Grok more training data. We end up paying X for visibility, so X profits twice from the same creators.
English
1
1
12
1.7K
Panos Gkatziroulis 🦄
@Cyb3rMonk @m19o__ Most of the topics can be learned with an LLM, the only differentiator in my opinion is how to pass real-world experience/use cases in the material and bring the human element.
English
1
0
0
105
Panos Gkatziroulis 🦄 retweetledi
Panos Gkatziroulis 🦄
Which format do you prefer for learning technical content in a course?
English
1
1
2
2.9K
Panos Gkatziroulis 🦄
Working towards a new article about emulation and detection of EntryPoint injection.
Panos Gkatziroulis 🦄 tweet media
English
0
0
14
1.8K
AbuMuslim (أبومُسْلِم)
The modern learning experience needs to become far more interactive. Text-heavy courses are losing ground, especially when anyone can now ask an LLM for quick explanations. What will stand out more is strong visual teaching, creative UX, and content that makes people interact, not just read.
English
1
0
2
138
R136a1
R136a1@TheEnergyStory·
Have you noticed that those deep-dive stories about complex Windows malware have pretty much vanished, especially in recent years? It feels like the era of "blockbuster" Windows malware has just gone silent, and this blog post tries to give some answers why. r136a1.dev/2026/05/07/whe…
English
18
131
592
79.3K
Panos Gkatziroulis 🦄 retweetledi
Nasreddine Bencherchali
A couple years ago I wrote a blog on Dllhost and what it is actually running. I decided to revisit it this time around from a RE perspective and answer that conclusively. From CLI to the registry value. Read the research - research.nasbench.dev/research/windo… TL;DR - Dllhost is just a wrapper around CoRegisterSurrogateEx. It register but does not execute. Thats a job for combase.dll. Hence why it cannot be used as a LOLBIN directly. There are also additional fun facts in there. Enjoy!
Nasreddine Bencherchali tweet media
English
1
26
99
5.6K
Panos Gkatziroulis 🦄 retweetledi
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Silencing ETW Threat Intelligence via BYOVD New Medium post. Today I will show you how to disable the ETW Threat Intelligence provider at the kernel level using a vulnerable driver as a read/write primitive @s12deff/silencing-etw-threat-intelligence-via-byovd-c2ba9e3bb072" target="_blank" rel="nofollow noopener">medium.com/@s12deff/silen…
English
0
8
46
2.8K
Panos Gkatziroulis 🦄
🚨 Cross‑Session Activation is a detection gap hiding in plain sight. 💡 The technique abstract below highlights the minimum viable signals for defenders. 💭 Interesting to know if this technique is part of your threat emulation library. #detectionengineering #purpleteam #blueteam
Panos Gkatziroulis 🦄 tweet media
English
0
1
4
1.3K
Panos Gkatziroulis 🦄
🚨 Cross‑Session Activation is a detection gap hiding in plain sight. 💡 The technique abstract below highlights the detection opportunities for defenders. 🟣 If you’re conducting purple‑team testing, this technique should already be in your playbooks. #detectionengineering #purpleteam #blueteam
Panos Gkatziroulis 🦄 tweet media
English
0
0
2
790
Panos Gkatziroulis 🦄 retweetledi
Panos Gkatziroulis 🦄 retweetledi
shenetworks
shenetworks@shenetworks·
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
English
177
269
1.9K
285.7K