dr0pd34d

2.6K posts

dr0pd34d banner
dr0pd34d

dr0pd34d

@st3ff3n_com

Red Team

Katılım Şubat 2016
176 Takip Edilen144 Takipçiler
dr0pd34d
dr0pd34d@st3ff3n_com·
@tombombadeel @yadong_xie Fully understandable and also the fun part about it 😁 Otherwise you could buy a ready made product
English
0
0
0
25
Tom
Tom@tombombadeel·
@st3ff3n_com @yadong_xie I could package and share the repo but I’m not a coder, so literally all of it is vibe coded, so I’d be worried about my repo breaking someone’s stuff because it’s not close to a finalized state at the moment It’s more fun to let codex cook anyway! Have fun tinkering
English
1
0
1
57
Yadong Xie
Yadong Xie@yadong_xie·
把 claude desktop buddy 移植到了我的 esp32-s3-amoled 设备上 真正的编程搭子,花的 token 越多,level 越高
Yadong Xie tweet mediaYadong Xie tweet mediaYadong Xie tweet media
中文
28
65
1.2K
169.6K
dr0pd34d
dr0pd34d@st3ff3n_com·
@tombombadeel @yadong_xie Oh boy then my ARM Macbook is up for a challenge but thanks for the tips 😂 Should arrive in two days, lets see if I can build a little buddy
English
1
0
1
43
Tom
Tom@tombombadeel·
@st3ff3n_com @yadong_xie FYI if you have a windows computer it’ll work right away and Codex or Claude Code can flash it easily due to what it shipped with macOS took a lot of effort from codex and actually totally wiped the boot off of it and I thought it was bricked 😅 codex on windows recovered it
English
1
0
0
176
dr0pd34d
dr0pd34d@st3ff3n_com·
@tombombadeel @yadong_xie I ordered one based on this thread and hope I can get it to run 😂 No idea but maybe the AI overlords can help
English
1
0
0
49
Tom
Tom@tombombadeel·
@yadong_xie It’s cool that we’re all building the same things around the world. Here’s my current take with an ESP32-S3 LCD with a prism hologram
English
5
1
30
6K
dr0pd34d
dr0pd34d@st3ff3n_com·
@0xCVYH It did 10 Tokens/s in LM Studio and also felt faster in MLX-LM. I thought using oMLX would give me a speed boost but seems it did not.
English
1
0
1
54
dr0pd34d
dr0pd34d@st3ff3n_com·
@0xCVYH I tried oMLX with Qwopus3.5-9B-v3-HLWQ-MLX-4bit and got: Prompt Processing (excl. cached) - 32.4 tok/s - Token Generation - 0.6 tok/s. I assume I have to try a much smaller model then 🥲
English
2
0
1
52
CV.YH
CV.YH@0xCVYH·
Qwen 3.6-35B-A3B saiu hoje de manha. HLWQ CT INT4 publicado HOJE mesmo — mesmo dia, modelo rodando em RTX 3060 12GB. 70.2 GB BF16 → 19.4 GB quantizado (-72%). com expert cache=8: ~5 GB VRAM efetivo (-93% do baseline). cache=2: ~3 GB (cabe em GPU de 6GB). arquitetura: 40 layers, 256 experts/layer, hibrido Gated DeltaNet + Full Attention, contexto 262k tokens. 30.720 expert weights quantizados individualmente. um modelo de 35B param MoE, agentic-first, rodando consumer GPU no dia do lancamento. o gap entre release frontier e compatibilidade consumer acabou de fechar pra zero huggingface.co/caiovicentino1…
Português
13
23
270
12.9K
dr0pd34d
dr0pd34d@st3ff3n_com·
@0xCVYH Anything you can recommend for agentic coding? I guess with that file size the results are all not really usable. :(
English
0
0
1
13
dr0pd34d
dr0pd34d@st3ff3n_com·
@0xCVYH Thanks will give it a try and report back 😊
English
1
0
1
31
CV.YH
CV.YH@0xCVYH·
yes — M1 16GB handles 9B-class via MLX comfortably. two HLWQ variants ready on HF: • Qwopus3.5-9B-v3 (Claude Opus distill) → huggingface.co/caiovicentino1… • Qwen3.5-9B base → huggingface.co/caiovicentino1… load with mlx-lm, should run ~30-40 tok/s on M1. for the 31B Opus+Vision i posted, M1 16GB is too tight — you'd need M2/M3 Max 48GB+ or M4 Pro 36GB. but 9B covers most coding/agent use cases
English
2
0
3
304
dr0pd34d
dr0pd34d@st3ff3n_com·
@LocallyAIApp I assume Gemma 4 is in the pipeline as well? ;) Is there a possibility in the future to integrate a HF search and download to cover more and other models as well?
English
0
0
0
3
R136a1
R136a1@TheEnergyStory·
TeamPCP msbuild.exe Malware Analysis Here is a breakdown of the execution chain, featuring EDR bypasses and steganography. 🛡️ 1. Evasion • Dynamic SSN Resolution: The malware resolves native API functions (e.g., ZwAllocateVirtualMemory, NtProtectVirtualMemory) by matching their DJB2 hashes to dynamically extract their Syscall Service Numbers (SSNs). • Trampoline Syscalls: To bypass EDR user-land hooks, it then searches the ntdll.dll .text section for the first occurrence of a clean syscall; ret gadget (0x0f05C3), typically finding it inside NtAccessCheck. • Custom Syscall Stubs: Finally, it uses the extracted SSNs with custom syscall stubs. These stubs load the appropriate registers and jump to the located ntdll.dll gadget, cleanly executing indirect syscalls from a legitimate memory region. • ETW Blinding: Neutralizes telemetry by patching the first instruction of EtwEventWrite with 0xC3 (ret). 🖼️ 2. Steganography • Spawns a suspended dllhost.exe child process. • Extracts the Adaptix C2 payload (shellcode loader + payload) embedded into the Red, Green, and Blue color channels of the image, while locking the Alpha (transparency) channel to fully opaque (FF). • Writes the payload directly into an allocated buffer in dllhost.exe. 💉 3. Injection • Instead of relying on one method, it sequentially tries multiple techniques to execute the payload in dllhost.exe: 1️⃣ APC Injection: NtQueueApcThread, NtResumeThread 2️⃣ Thread Execution Hijacking: ZwGetContextThread, ZwSetContextThread, NtResumeThread 3️⃣ Remote Thread Injection: NtCreateThreadEx, NtResumeThread (Note: APIs for process hollowing and doppelgänging are also present but remain unused). 📡 4. Adaptix C2 Payload • C2 URL: checkmarx[.]zone/telemetry/checkmarx.json (Defanged) • Exfiltration: HTTP POST requests using the X-Content-ID header for encoded/encrypted data. • User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0 🔬 5. IOCs • Analyzed Sample: virustotal.com/gui/file/72903… • Related Sample: virustotal.com/gui/file/a985b… Overall, a nice mix of methods, but nothing novel.
English
11
81
438
54K
dr0pd34d
dr0pd34d@st3ff3n_com·
@faisalusuf @aylacroft This is true, however there are cases where the CVs are theoretical planned members and staffing changes until execution due to projects, leaves, sickness. But in general the people should know what they are doing 😅
English
1
0
1
15
Faisal
Faisal@faisalusuf·
@aylacroft A practice is before any red team engagement the profiles and credentials are requested for participating parties. This is the first step before awarding the project. You should know who you are allowing to touch your systems.
English
3
0
6
474
Ayla Croft
Ayla Croft@aylacroft·
Question... if you hired a company for red teaming & found out that the "red teamers" were actually random new to the industry what would you do? Would you respect a security company that paid out so little that only noobs were interested in red teaming?
English
20
0
42
9K
dr0pd34d
dr0pd34d@st3ff3n_com·
@hakluke I think AI should not be allowed in the contests and has to be declared up front. Winning then „being the good person and giving up the win“ is not fair to the rest of the contestants. I would be interested in AI only CTFs however 😁
English
0
0
1
229
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
I just won the CTF at CrikeyCon, beating whole teams of experienced pentesters. I did it using a custom AI setup. The same AI setup that I’m using to crush bug bounties and find 0days. The industry is changing faster than most people realise. I’m writing a blog to explain exactly how it works. Follow me to see the blog when it drops!
English
21
26
648
41.6K
dr0pd34d
dr0pd34d@st3ff3n_com·
@cerbersec @uwu_underground I do however agree that machine learning can be quite annoying. I can think of a specific EDR vendor that magically discovers and flags PE files that way and I think it is great. I hope to see more of those features. Makes the job harder but hey also for the attackers.
English
0
0
0
18
Cerbersec
Cerbersec@cerbersec·
@uwu_underground I'm all for the psyop, but this post is cap. AI/ML in EDRs has been a thing for a while, it doesn't require targeted attacks to evade or exploit. Any half decent attacker will try to blend in and use legitimate actions to break up telemetry or generate FPs, that's not new
English
3
0
6
435
UwU Underground
UwU Underground@uwu_underground·
With the adaption of ML and AI modeling in virtually all EDRs right now every attacker should be weaknesses against learning systems. If you aren't learning or studying about model evasions, model poisoning, data drift exploitation, or telemetry attacks its gonna be EOL for ya
English
9
18
125
7.4K
dr0pd34d
dr0pd34d@st3ff3n_com·
@Tw1sm Cool! I had the same idea and also made one. Realized quickly that UI placement with Gemini was a bit of a pain to get lines to where they belong and to not have information overlapping. But pretty neat to have indeed!
English
0
0
1
195
Matt Creel
Matt Creel@Tw1sm·
Vibed up a quick tool to visualize and stack significant red/blue events that occurred during an assessment. Have always liked including a high-level visual like this in debriefs but made them by hand in the past using something like draw[.]io
English
6
18
91
7.4K
dr0pd34d
dr0pd34d@st3ff3n_com·
@ivanfioravanti Looks nice! If only that setup would not cost 12.000€ here.
English
0
0
0
24
Ivan Fioravanti ᯅ
Ivan Fioravanti ᯅ@ivanfioravanti·
MLX MiniMax 2.5 running LOCALLY on a single M3 Ultra 512GB! Writing a poem on LLMs at 6bit quantization! 🔥 Let's start some coding, context and distributed tests! Generation: 40.2 tokens-per-sec Peak memory: 186 GB
English
103
137
1.8K
225.9K
dr0pd34d
dr0pd34d@st3ff3n_com·
@AlexFinn Does M2.5 run on these two single devices?
English
0
0
0
45
Alex Finn
Alex Finn@AlexFinn·
We have entered a new age An open source model just released that is: • Better than Opus 4.6 for coding • Faster than Sonnet • State of the art for tool calling I will be running Opus level superintelligence on my desk. For free. This quite literally changes everything I will now be able to have a super intelligent AI model powering my OpenClaw that will search through X and Reddit 24/7/365 finding challenges to solve, then building apps out to solve those challenges, then shipping the apps live All autonomously A full, autonomous, software factory on my desk running 24/7 for free. Imagine what happens when people realize what's now possible. Totally secure, private, unlimited, free in your home super intelligence. Nothing will be the same
Alex Finn tweet media
MiniMax (official)@MiniMax_AI

Introducing M2.5, an open-source frontier model designed for real-world productivity. - SOTA performance at coding (SWE-Bench Verified 80.2%), search (BrowseComp 76.3%), agentic tool-calling (BFCL 76.8%) & office work. - Optimized for efficient execution, 37% faster at complex tasks. - At $1 per hour with 100 tps, infinite scaling of long-horizon agents now economically possible MiniMax Agent: agent.minimax.io API: platform.minimax.io CodingPlan: platform.minimax.io/subscribe/codi…

English
588
532
7.7K
3.1M
Cerbersec
Cerbersec@cerbersec·
idk how people use agentic coding flows without going broke. I run out of tokens after 3 prompts (╯°□°)╯︵ ┻━┻
English
2
0
4
718
dr0pd34d retweetledi
EFF
EFF@EFF·
Thankfully, public pressure has once again pushed the EU Council to withdraw its dangerous plan to scan encrypted messages. eff.org/deeplinks/2025…
English
2
17
79
6.4K
dr0pd34d retweetledi
Zeroed
Zeroed@Zeroedtech·
I've recently been experimenting with using .NET profilers to hook .NET functions under IIS and decided to write up a blog post while it was fresh in my mind zeroed.tech/blog/hooking-n…
English
1
31
105
9.8K