Red Team | Offensive Tool Dev | 2x Course Author @ Zero-Point Security

After over a year of work my second course with @_ZeroPointSec is now available! In it students will apply low level windows tradecraft in the writing of Cobalt Strike’s UDRL and Sleepmask components. To celebrate, the BOF course is 25% off thru Jan 12th! zeropointsecurity.co.uk/cour…
4
50
189
18,282
Octoberfest7 retweeted
Guess what... @fortraofficial / @_ZeroPointSec are looking for a new content developer to join our ranks. fortra.wd12.myworkdayjobs.co…
1
11
37
4,554
Woof
New: from 404 Media. The catastrophic FBI hack also exposed the FBI's own hacking unit. The Remote Operations Unit is a highly secretive part of the FBI, responsible for making tools to break into peoples' devices. Some of their names are in the data 404media.co/fbi-hack-exposed…
2
16
6,181
After finally getting to see how CrowdStrike works in action and also receiving a nastygram from them threatening to cancel my account for doing so, I come to conclude that both the product and company have soft hands.
7
10
160
13,234
I’m about 98% of the way to adding “AI”, “agentic”, and “benchmark” to my muted words list. A piece of me worries about falling behind in offensive cyber, but the hype and noise around this shit is beyond obnoxious
4
3
97
3,864
Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC. Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services. Blog post soon with potential abuse vectors.
7
93
378
19,795
My favorite class of bug? The kind that’s in my own tooling and only causes crashes when a debugger is NOT attached 🫠
1
31
1,561
Octoberfest7 retweeted
I think the red team community has placed too much emphasis on "getting DA". Getting admin access should prove useful to a much larger objective. An attacker can likely achieve extensive impact to an organization by leveraging the access of a sales representative, let alone an administrator
3
4
21
4,368
The decreasing AI use limits and reactions to them are interesting. I have a $20/mo Claude subscription that’s effectively my new Google that I rarely if ever hit my quota on. Meanwhile I read about people avg $1000/day in usage. If/when the music stops people will be in trouble
5
26
5,041
Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet. Now you can. Enjoy! netspi.com/blog/technical-bl…
15
197
753
67,623
It’s a brave new world.
My biggest concern with private sector offensive action vs crime – having run the global cybercrime & ransomware intelligence team for almost 4 years – is just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right (including certain gov agencies). People are regularly and willingly wrong on pretty important incidents. whitehouse.gov/presidential-…
1
10
2,040
Octoberfest7 retweeted
Taps sign.
3
4
65
4,921
Provided the US manages to pull out of the moral tailspin it’s in, I eagerly await any and all consequences for the entities who have so recklessly and unabashedly chased profit at the expense of society and the rule of law.
I've watched the BlackHat OpenAI talk on the containment escape and HuggingFace attack that's now on YouTube. The incident was far worse than initially conveyed. Not in technical details. But in the absolutely jaw-dropping levels of recklessness (true recklessness) at OpenAI. 🧵
1
1
22
3,393
We just got a little more offensive... Please join us in welcoming Ryan Zagrodnik and TJ Toterhi to Red Siege! We're thrilled to add their experience and expertise to the team. Welcome to the squad! 😎 #weareoffensive #hacking #infosec #cybersecurity
1
4
501
Octoberfest7 retweeted
Alex Reid's (@Octoberfest73) UDRL & Sleepmask course is already the gold standard for deep diving on these expansive @_CobaltStrike features. Now it just got better. Updated for the latest version, plus four new modules. zeropointsecurity.co.uk/cour…
8
35
2,289
Interesting tidbit tucked in this remarkable research:
New blog Spent way too much time reverse engineering CrowdStrike Falcon. Somewhere along the way, I found a bug. It's low and not practically exploitable... but a bug is a bug :) Publishing soon 0xdbgman.github.io/posts/ins…
1
3
31
3,968
The first major update to my UDRL and Sleepmask Dev course is now live (and free for existing students)! A lot of work and novel research is included in four additional lessons, the details of which can be found in the comments below🙂 Course page: zeropointsecurity.co.uk/cour…
10
7
75
4,785
BeaconGate Support for BOFs: Explores how to add BeaconGate functionality for arbitrary Windows APIs of students choosing, resulting in any BOFs that utilize them routing the calls through BeaconGate without requiring modifications to the BOFs themselves.
3
394
Alpharius - A CET-Compliant Stack Spoofing and Sleep Obfuscation Technique Utilizing Fibers: Explores Intel CET and its impact on stack spoofing techniques. Outlines and implements a novel CET-compliant stack spoofing / sleepmask mechanism replacing the use of timers / Ekko.
4
262
Loading Sensitive Libraries via Proxy: Addresses anincreasingly common detection rule found in EDRs concerning the loading of suspicious DLLs into a process. Examines when these libraries are loaded during the Beacon reflective loading process and resolves w/ call stack spoofing
5
357
Lightweight BeaconGate and Runtime Configuration BOF: Adds an abbreviated obfuscation process for BeaconGate calls for efficiency. Also covers the creation of a Beacon Object File (BOF) that can be used to toggle the mechanism between the abbreviated version and the full one.
5
375