SensePost

@sensepost.com

Work like hell, Share all you know, Abide by your handshake, Have fun. - Dan Geer

Really excited to present this Frida training @1ns0mn1h4ck.bsky.social with @ipmegladon.bsky.social and myself! If you've dabbled with Frida before, but want a practical learning opportunity to improve your usage and understanding, this one is for you!

Insomni'hack @1ns0mn1h4ck.bsky.social · 7mo ago

Learn how to bypass security controls using Frida at #InsomniHack workshop. "Binary Instrumentation with Frida" is led by SensePost and it is made for reverse engineers, pentesters & security researchers. Get your ticket: https://ow.ly/lTxz50XVBJm #Cybersecurity #Infosec #INSO2026 #Cyberworkshops

I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)

The proxy view for PipeTap, a Windows Named Pipe Analysis Tool

Whipped together a SOCKS5-over-any-transport feature today for the c2 & implant used in @sensepost.com purple teaming / emulation exercises. Here I have a cURL request, over an ICMP channel, funnelling HTTP requests in and out via our implant :D Fun! 😄🔥

C2 console logs showing a SOCKS5 proxy having started on port 1800Implant logs showing an ICMP channel enabled, HTTP channel disabled and a proxy server started targeting the ICMP channel.cURL configured to use a SOCKS5 proxy (pointing at the C2), targeting an IP on the other side of the implant.

Instead of relying on RemCom, what if we had a python client to interact with the latest, Microsoft signed PSExec? In this post Aurélien details how he and the team did exactly this, including a tool, some PSExec internals and detection opportunities! sensepost.com/blog/2025/ps...

Bild