@raphaelmudge.bsky.social I gotta ask, why are tcg releases not on something easier to script pull like github lol, plz my docker images are in pain
In his latest research, Michael Grafnetter looks at Okta attack paths, and where they actually show up. Not in Okta itself, but in everything connected to it. With OktaHound you can map that in BloodHound. Check it out: https://ghst.ly/4t1UcHl
Discovering Unexpected Okta Attack Paths with BloodHound - SpecterOps
OktaHound is a new data collector for the Okta Platform that ingests information about entities and their relationships within an Okta organization and represents them as nodes and edges in BloodHound...
ghst.ly
Early career pen tester wanted to break some of azures specialist clouds. #infosecJobs
Penetration Tester | Microsoft Careers
Penetration Testing Identify security vulnerabilities and variants across critical cloud services. Perform source code reviews, dynamic analysis, and operational security assessments. Validate softwar...
apply.careers.microsoft.com
GitGoon: Git for gooners Tired of your Pokemon Stadium mod to give Lapras heckin bonkers getting taken down by GitHub? Worry no more. gitgoon.dev
GitGoon: Git for gooners
Forgejo is a self-hosted lightweight software forge. Easy to install and low maintenance, it just does the job.
gitgoon.dev
TCG's vision is to separate tradecraft from capability and encourage an ecosystem of ground truth research. I started w/ UDRLs because the need & interfaces are there. This post applies the same ideas to BOFs. Each working tradecraft/capability pairing is a win. Some caveats (see post), exciting.
[BLOG] BOF Cocktails rastamouse.me/bof-cocktails/
my man, you don't need all those certs in your name
Not the full system prompt, but I was able to dump the rules from the DOGEAI_Gov Twitter account. The one that constantly dick rides Elon and Trump.
"I'm happy to report I'm just fine. I lost a button. But I'm gonna sleep in my bed tonight, safe, with my family... At that elevator, I was separated from someone named Edgardo... Edgardo is in ICE detention and he's not going to sleep in his bed tonight."
Embracing my nostalgia for the old steam interface by using it in Mythic
"AI is going to put all the devs out of the job" AI when asked to update a class
Now these are some policies and procedures I can get behind
Hi I’m a professional YouTuber and I’m starting to have sponsors back out of contracts because tariffs. I’ve done well for many years and I’m not worried about myself; I merely offer this information as an anecdotal indicator.
Just wait until the moment podcasters realize that tariff-induced ecommerce bankruptcies are causing their ad money to dry up. That's when consumer sentiment is really going to drop like a lead balloon.
you know when Visual Studio switches from (MB) to (GB) you're about to have a good time
This has been a LONG time coming! This is just the beginning though :) I'll be recording more videos for updates, new features, workflow enhancements, and yes - a developer series too! Be sure to let me know what you do/don't like about this format and what kinds of things you'd like to see!
Mastering Mythic doesn't have to be complicated. 😵💫 Check out our operator-focused video series w/ @its-a-feature.bsky.social, which cuts through the noise & delivers exactly what you need to customize & leverage Mythic effectively. 👀: ghst.ly/mythic-op
Windows OpenSSH agent will store SSH keys under "HKCU:Software\OpenSSH\Agent\Keys". It's on my TODO list to write a tool that will extract these and decrypt them if needed
Haven't seen much TTP sharing on bsky. So in order to help start to be the solution, for the next few days I'm going to share some of my favorite places to find secrets such as SSH Keys, Credential Objects, Access Tokens, and other stuff that usually gets forgotten about.
You don't have to know how to code to be a good red teamer. However, knowing how to will help you stand out, especially in the beginning of your career
Haven't seen much TTP sharing on bsky. So in order to help start to be the solution, for the next few days I'm going to share some of my favorite places to find secrets such as SSH Keys, Credential Objects, Access Tokens, and other stuff that usually gets forgotten about.
Was not expecting to jump on a meeting and see @malwarejake.bsky.social today
If someone wanted to phish me, I do accept backdoored graphics cards
Sure, we could just provide this as a goddamn text file, but then you couldn't virtue signal your techbro-ness. Might as well have a shitty AI pump a bit of Co2 into the air for the text because VIBES
Ransomware but instead of encrypting files, it calls the Beep Api at random intervals and doesn't stop until you pay
#MythicTip Not a fan of Mythic's UI colors? Change them! Click the cog for your user settings and change all the colors for light and dark separately for what you prefer! You can export/import these with the buttons at the top too for easy reuse. Background images also work 🫣