Senior Adversarial Engineer Member of EVILCORP\Domain Fathers rayrt.gitlab.io cyllex.io/

Pinned Tweet
Introducing Cyllex - Advanced APT Emulation Framework. cyllex.io/ I've been working on this for a while, pouring real effort and love into it. Not a quick release, I'm going step by step, building something solid. Some of the current features include: ▸ APT database with real-world campaign emulation ▸ Cross-platform agents via binary patching ▸ Agent, Agentless (WinRM/SSH), and Cloud execution ▸ Direct shell access for real-time interaction ▸ Interactive MITRE ATT&CK detection coverage tracking ▸ Calendar-based campaign scheduling ▸ Webhook notifications (Slack, Teams...) ▸ Robust TTPs: On-Premise (Windows/Linux), Cloud, and Containers I'll be sharing updates as the project evolves. Thank you, and happy new year!
8
53
240
15,975
InjectSetConsole - Performs process code injection by leveraging a Windows named pipe. Unlike traditional techniques, it does not use the: ✅ VirtualAllocEx & ✅ WriteProcessMemory APIs github.com/TwoSevenOneT/Inje…
4
37
145
7,250
_Ray retweeted
New Release Havoc Professional 0.8: Leviathan 🩸 - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored port forwarding and sleep masking - Enhanced .NET/PowerSafe execution - In-Memory PE Execution and BOF-PE support - HTTP/s Server Name Indication (SNI) Spoofing - License Updates / Air-gapped licensing - Havoc client UI overhaul & cross-platform support Release Link Below🔗
15
41
267
12,088
When I started ipurple.team/ two years ago, my goal was to give SOC teams practical detection opportunities across some of the most modern adversarial techniques. So far, I’ve documented 25 techniques, and every article includes: ✅ SIGMA Rules ✅ Sysmon Configs ✅ Threat Hunting Queries If you work in Purple Teaming, Detection Engineering, Threat Hunting, or even the Red Team space, and you want your MITRE ATT&CK coverage to look like the example below, dive into the articles, start emulating, and begin hunting. If you know that someone else in your network will benefit, feel free to repost.
4
67
308
16,125
New writeup: Patch-Gap Zero-Days: BlueMoon. Five China-nexus clusters chained two V8 patch-gap bugs (CVE-2026-85046, CVE-2026-87491) to one Windows ALPC LPE zero-day (CVE-2026-85880) against Chrome on Windows. cyllex.io/blog/posts/bluemoo…
4
3
623
_Ray retweeted
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: outflank.nl/blog/2026/09/08/…
7
160
450
34,137
Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC. Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services. Blog post soon with potential abuse vectors.
7
93
378
19,841
_Ray retweeted
Introducing SpecterOps Skills: a public repository built to turn practitioner knowledge into reusable, reviewable workflows for AI-assisted security work. @zinic shares what we're building, why we're building it, and how you can contribute ➡️ ghst.ly/4ybT6ew
43
177
14,883
FalconFlank : Crowdstrike Falcon 0day LPE is now public github.com/MSNightmare/Falco…
91
503
2,915
365,435
CrystalPotato is a Crystal port of GodPotato with indirect syscalls, dynamic API resolution and compile-time string obfuscation github.com/ricardojoserf/Cry…
2
26
104
5,200
_Ray retweeted
plugandpwn.com/ 👀👀👀
2
18
150
28,209
_Ray retweeted
You don't need a USB. You need to look like one. Emulate the device, Windows fetches a signed package off Windows Update and runs vendor code as SYSTEM. Arbitrary code execution, LPE, standard user or empty logon screen. DEF CON 34 talk w/ @Qm9yamFN. Link at the first comment.
18
268
1,274
144,043
_Ray retweeted
I just wrote a post for @AdeptsOf0xCC! Yes, we are live again! 🦉 In this post I RE a sound protocol (yes soundwaves!) used by Eufy and also we recover and decrypt wifi credentials from its flash memory. From your doorbell to your home network => adepts.of0x.cc/eufy-doorbell…
10
13
1,403
‼️ Hugging Face built an interactive replay of the OpenAI agent that breached them. It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream and more. huggingface-anatomy-of-front…
51
446
2,611
211,266
_Ray retweeted
Happy to share a technical analysis by @h0j3n on our recent CVE-2026-54121 a.k.a Certighost. glhf🔥 Technical analysis: gist.github.com/H0j3n/a5ef26… POC: github.com/aniqfakhrul/CVE-2…
11
255
715
101,461
1/4 He acabado "Crónicas del Red Team", de @TheXC3LL y lo he disfrutado muchísimo. Desde que comencé en seguridad ofensiva, allá por 2017, siempre he tenido la suerte de coincidir con grandes profesionales de los que he aprendido muchísimo.
1
4
2,062
3/4 Leer las distintas operaciones (mi favorita ha sido Operación Cinta Roja) y ver cómo Juanma convertía momentos de frustración en ideas locas que terminaban sacando los objetivos adelante ha sido genial.
1
120
4/4 Me ha parecido muy interesante y, sobre todo, muy motivador. En definitiva, un libro muy recomendable, tanto por su contenido técnico como por el lado humano que transmite.
108