Leo Loobeek

570 posts

Leo Loobeek

Leo Loobeek

@leoloobeek

Penetration Tester | Adaptable Adversary | https://t.co/hHYXI8KHIg | Thoughts and tweets are my own

Minnesota, USA Katılım Temmuz 2009
449 Takip Edilen1.4K Takipçiler
TheDistance
TheDistance@TheDistance21·
Hitting the road for annual golf trip to Northern Minnesota, where we play two (sometimes 3) of the nicest public courses in the state. Wish me luck. When I come back, I hope to see JJ McCarthy make major strides in his progression as our number 1 QB.
English
1
0
4
208
Leo Loobeek retweetledi
Jason Lang
Jason Lang@curi0usJack·
Welcome to my 2023 Irreverant Red Team TTP Wrap Up (Trends, Trolls, Predictions) It's likely some of these will ruffle feathers, but hackers break things right? 😁 🧵👇
English
4
65
288
61.9K
Leo Loobeek retweetledi
Dave
Dave@dtpkll·
@Vikings @KevOC7 @PhilMackey @DustBaker Season over. 24 hours after the most devastating event of his career, OUR quarterback doesn’t sit home feeling sorry for himself. No, he attends the Kids Club Trick-Or-Treat Trail in Egan. That’s our QB. #Vikings
Dave tweet media
English
72
344
3.7K
540.7K
Leo Loobeek retweetledi
moo
moo@moo_hax·
Fun little DLL making a request out to an LLM. Still have some troubleshooting left with sRDI. While it’s ultimately just a we request, LLMs + Ops os fun to think about.
moo tweet media
English
0
3
13
2.2K
Leo Loobeek retweetledi
moo
moo@moo_hax·
Before NVIDIA, I was lucky enough to work with @ram_ssk and @drhyrum at Microsoft. We got to write tooling, risk assessments, and attacks IRL. MLSec seems new, but their work on this topic is all over the Security community. If you’re looking to orient yourself to the current state of ML Security, this is it. amazon.com/Not-Bug-But-St…
English
7
7
33
5.7K
Chris Spehn
Chris Spehn@ConsciousHacker·
I'm convinced COM is a powered by a wizard inside of a hamster wheel and no one can talk to the wizard. Therefore, no one really knows how COM actually works.
GIF
English
6
1
44
5.8K
bohops
bohops@bohops·
@coffeegist It's really a social experiment to see who is still hanging out on this platform...
English
1
0
1
0
Leo Loobeek retweetledi
Kiwids
Kiwids@mhskai2017·
I wrote a blog post that talks about how we can abuse yet another Chrome Remote Debugging feature to "stalk" end users. posts.specterops.io/stalking-insid…
English
2
44
76
0
Leo Loobeek retweetledi
Jackson T.
Jackson T.@Jackson_T·
In this post, I discuss one key difference in the thinking between sophisticated adversaries and many of the red teams that try to simulate them, as well as what that means for tradecraft and tooling. jackson_t.gitlab.io/it-depends.html
Jackson T. tweet media
English
5
93
269
0
Leo Loobeek retweetledi
OtterHacker
OtterHacker@OtterHacker·
An interesting post about Kernel Callback used by EDR. It’s a nice article to read if you want to dive into EDR Kernel Callbacks bypass. Thanks @synzack21 for the blogpost ! :) The part about @fdiskyou evil.sys driver and experiments is really nice ! :) #patching-the-edr-process-notify-callback" target="_blank" rel="nofollow noopener">synzack.github.io/Blinding-EDR-O…
English
0
51
117
0
Leo Loobeek
Leo Loobeek@leoloobeek·
@subTee Thanks Casey! Just standing on the shoulders of all your great work 👊
English
0
0
1
0
Leo Loobeek retweetledi
Karl
Karl@kfosaaen·
Packt currently has a few books (including Penetration Testing Azure for Ethical Hackers) on sale on Amazon. Use code “20SECURITY” to get the 20% off discount - packt.link/NEBPw
English
0
4
6
0
Leo Loobeek retweetledi
Matt Eidelberg
Matt Eidelberg@Tyl0us·
Introducing Ivy a unique, stealthy method of executing shellcode using VBA and COM objects without dropping office macro documents to disk. Ivy also allows for the unhooking EDRs from the VBA environment. Check it out: github.com/optiv/Ivy 👀 #netsec #redteam #EDR #evasion
English
9
318
670
0
Leo Loobeek retweetledi
bohops
bohops@bohops·
AccChecker is a pretty interesting #lolbin (+ AppLocker Bypass) from the Win SDK. Load a managed DLL with this cmd: AccCheckConsole.exe -window "Untitled - Notepad" C:\path\to\your\lolbas.dll More info in this gist: gist.github.com/bohops/2444129…
English
3
74
171
0
Leo Loobeek retweetledi
Jonas L
Jonas L@jonasLyk·
github.com/jonaslyk/temp/… My webdav based reflective loader/per process devicemap based dll injector POC is by now usable. I would really like to have a OOP wrapper for NT- designing such is surprisingly difficult, but this approach shows potential especially considering simple
English
3
90
263
0