Pentesting, scripting, pwning!

127.0.0.1
Check this out if you didn't already, more to follow! 🔥🤠
Our first Blog post is live, Introduction to RustPack 🔥 msecops.de/blog/posts/rustpa… More to follow in the future for sure!
4
28
6,286
Anyone likes Snaffler? Want to run it from Linux with a nice HTML report and filtering options? Now you can: github.com/S3cur3Th1sSh1t/Sn…
6
42
199
11,723
Opus 4.8 says no because of cyber. Ok than let Opus 5.0 do it 🤣
5
7
138
14,400
While on the train I was wondering how Claude Code is sending messages from one session to another. This is how and you can manually inject "teammate" messages yourself: github.com/S3cur3Th1sSh1t/cl…
2
4
41
5,144
S3cur3Th1sSh1t retweeted
New Blogpost regarding to "Backdooring Open-Weight Models" just published by @ShitSecure: msecops.de/blog/posts/backdo…
22
72
11,884
First offensive talk today from Karan Raheja and @IndiShell1046 about weaponising IIS for Active Directory Post Exploitation. 🙌 @MCTTP_Con
2
5
23
3,507
RT @Enno_Insinuator: .@ShitSecure & @KlezVirus sharing the work in their – really great – @MCTTP_Con talk ;-)
6
190
S3cur3Th1sSh1t retweeted
Can LNK files ever be trusted? ⚡ My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces tools to create your own LNKs, and detected spoofed ones yourself. 🐬 wietzebeukema.nl/blog/trust-…
12
232
1,005
145,095
Some new LNK abuse techniques from @Wietze at @MCTTP_Con 🔥
4
19
86
5,824
And another DCOM Lateral Movement technique released @MCTTP_Con by Shebin Mathew 🔥
2
30
138
7,310
S3cur3Th1sSh1t retweeted
I’m not worried about the future of pentesting and here’s why. The automated pentesting trend is following a similar trajectory as vulnerability scanning. Organizations only interested in compliance or those who have very small environments or budget will just go the automated route. Those who truly want to improve and who want expert guidance and consulting will go the manual or human-led route. The good thing is the automated route has gotten better and will continue to. But so will manual/human-led. There’s plenty of organizations to serve and to help in both categories. 🫡
12
9
54
5,674
S3cur3Th1sSh1t retweeted
[TALK] Tomorrow, Fabian and I will be presenting some of our latest research on device emulation and exploitation on Windows. Come say hi if you’re around! mcttp.de/2026-mosch-und-magn…
7
54
3,545
S3cur3Th1sSh1t retweeted
New blog post “Evading machine learning based detections” - msecops.de/blog/posts/ml-eva… 🔥
1
19
50
84,395
S3cur3Th1sSh1t retweeted
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
75
233
18,529
S3cur3Th1sSh1t retweeted
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: outflank.nl/blog/2026/09/08/…
7
160
450
34,085
GLM 5.3 Flash abliterated is 24x7 in a loop working on building exploits for vulnerable drivers. No need for me to do anything just letting it work till its finished 😎
11
21
347
21,170
S3cur3Th1sSh1t retweeted
🚨🚨🚨🚨🚨🚨 From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP[.]NET AJAX tantosec.com/blog/2026/09/te… The vulnerabilities described in this post were discovered, analysed, and exploited with some AI assistance, and a lot of old-fashioned human persistence.
1
59
181
31,832
S3cur3Th1sSh1t retweeted
This Model is amazing they really fixed the CVP guardrails.
37
27
361
58,985
Fiddling around with Qwen 3.8 27B to let it create a Packer/Loader and it was thinking more than 10 minutes about calc.bin file type and how to uncompress that with 7zip wtf? 😂Interrupted thinking there with additional infos who knows maybe it would have continued 60m or longer.
4
1
12
4,133
1 hour 5 minutes later its still reasoning and didnt write any line of code.
1
906
S3cur3Th1sSh1t retweeted
New release of DPLoot 🔥 Now DPLoot can recover secrets over multiple protocols : SMB, WMI, WinRM, MSSQL, Local and Cobalt Strike REST API. github.com/zblurx/dploot
3
36
113
6,571