We're delighted that ZephrSec is a sponsor for Hack Glasgow 2026! Founder @zephrfish.yxz.red is an experienced red teamer, author, regular attendee (and previous speaker) at our Hack Thursday meetup, and keen supporter of the cyber security community, especially in his home town of Glasgow.
Andy Gill
@zephrfish.yxz.red
Defcon goon, Adversarial Architect. Photography, Driving, Blog and general purveyor of chaos. Metal/DnB Fan creator and owner of https://lms.zsec.red
This year's event features @gabsmashh.bsky.social, Liam Follin, Scott McCracken, @zephrfish.yxz.red, Alex Close, Marie Dubremetz, Ken Munro, @akacki.net, Aaron Kelly, @gl4cier.bsky.social, Chris Bore, Michael Reimsbach, @rxerium.com, Ehren Osborne, [...]
pretalx.hackglasgow.live
Happy Hack Thursday, and happy Hack Glasgow speaker announcement! We're excited to announce that @zephrfish.yxz.red and Alex Close will be presenting 'The Hunted Becomes the Hunter: Catching Red Teamers and Pentesters and Spotting Adversarial Patterns' at Hack Glasgow!
It’s @bsidesleeds.bsky.social today and ZephrSec sponsoring. Come along to my talk talk at 11.40 in Track 1 all about blending into environments using defensive tools and understanding. Our 10% off coupon is also still live: LTR101-10Y lms.zsec.red
Red Team Training: MAE — Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
As we get ever closer to Saturday and the conference day, we wanted to put out another huge thank you to all of our fantastic sponsors ❤️ Genuinely, BSides Leeds would not be able to run without your support. We're so grateful that you were keen to be involved and help us make this happen!
Always happens when I take time off I end up writing things, here's the latest post blog.zsec.uk/baselining-w... all about learning the baselines of Windows, it doesn't cover everything and anything but I've spun up a lab with observability and tried to write some detections baselining. Enjoy!
🕹️ SPEAKER ANNOUNCEMENT 🎮️ We're excited to have @zephrfish.yxz.red presenting his talk 'Archaic Creativity: Pulling At Infinite Threads'. Catch Andy's talk on Track 1, and keep an eye on our website and socials for the full schedule release! #BSidesLeeds #SpeakerAnnouncement
It’s been 10 years since I published my first book(LTR101), so to celebrate I’m giving 10% off my red team course, Malwareless Adversarial Emulation (MAE). Check it out here: lms.zsec.red Discount code: LTR101-10Y Valid until the end of August 2026.
Red Team Training: MAE — Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
It's clear to see the amount of work that's gone into it — please do take a look: lms.zsec.red #HackGlasgow2026 #SponsorAnnouncement
Red Team Training: MAE — Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
We're delighted to announce ZephrSec as a sponsor for Hack Glasgow 2026! Founder @zephrfish.yxz.red is an experienced red teamer, author, regular attendee (and previous speaker) at our Hack Thursday meetup, and keen supporter of the cyber security community, especially in his home town of Glasgow.
Welcome onboard ZephrSec! 🎉 ZephrSec is all about giving back to the community, helping others grow through hands-on training, adversarial emulation, and real-world security insights. Levelling up the next generation of defenders & attackers 🚀 lms.zsec.red @zephrfish.yxz.red
This is what happens when I take time off, I actually write silly length blog posts and deep dive things blog.zsec.uk/bullyingllms/ the post dives into a MCP pipeline I've put together for autonomous 0day hunts.
Autonomous Vulnerability Hunting with MCP
Alt title: Bullying LLMs into submission to find 0days at scale
blog.zsec.uk
You've got till Friday 3rd to submit your talks and workshops. We've got plenty of talks but could do with a few more workshops, so if you've got an idea, but aren't sure, submit it anyway and let us decide forms.gle/hLXt1dibQrA6...
It's 4 weeks to the date since I launched ZephrSec Ltd LMS and Malwareless Adversarial Emulation(MAE), here's a blog post about a lot of the challenges, lessons learnt and general chaos of building and running your own platform and all the fun that follows building blog.zsec.uk/roll-your-ow...
Roll Your Own... LMS
People say don't roll your own crypto but nobody ever warns you not to roll your own LMS (when you have minimal dev experience).
blog.zsec.uk
With Easter coming up quick it is time for a date announcement. 1 March - CFP and call for crew opens 1 April - Pre talk announcement tickets 3 April CFP and CFC closes ~ 20 April speakers confirmed ~ 24 April main ticket drop Links and stuff coming closer to the dates.
Our first fully committed sponsor is @zephrfish.yxz.red. Long time supporter as a speaker and now a sponsor as well. Andy would like everyone to know about his Malwareless Adversarial Emulation training course lms.zsec.red We may be biased, but we reckon it is top quality stuff.
Red Team Training: MAE — Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
Since launching MAE over the weekend I’ve had a lot of great feedback from the community and I want to say how thankful I am for everyone’s support. One of the requests I had was for multi language support on subtitles, so I went ahead and added it to the platform. go check it out lms.zsec.red
I love watching my friends create awesome stuff. @zephrfish.yxz.red made some artisan, farm to table, shell to terminal red team training for you. lms.zsec.red
MAE - Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable. The course is at lms.zsec.red
Today’s the day, finally got around to publishing my red team course, with video, written and self spin up labs. lms.zsec.red
MAE - Malwareless Adversary Emulation
Advanced red team training — 13 modules on adversary emulation without traditional malware. Learn the techniques that bypass modern defences.
lms.zsec.red
Turns out I’m not very active on here or Twitter anymore even though over the years I’ve accumulated 19k followers on Twitter 😬
Made a thing, mucking about with python and a LDAP browser concept to ingest straight into BloodHound but also just a nice alternative to ADExplorer with fewer LDAP queries, simple LDAP browser using PyQt as a GUI and neo4j-driver to ingest into BH. github.com/ZephrFish/py... #bloodhound #redteam
GitHub - ZephrFish/pyLDAPGui: Python based GUI for browsing LDAP
Python based GUI for browsing LDAP. Contribute to ZephrFish/pyLDAPGui development by creating an account on GitHub.
github.com
Couple updates: Course Trailer and Sign Up: mae.zsec.red GoClipC2 - blog.zsec.uk/clippy-goes-...
Malwareless Adversarial Emulation | Living off the Knowledge
mae.zsec.red
Weekends are for random projects Here is a blog post all around Kerberos errors and a bonus interactive app built in collaboration with @thecontractor.io Errorism Index for Kerberos blog.zsec.uk/common-tool-... kerberos.errorism.io
Common Tool Errors - Kerberos
So you are performing your favourite kerberos attacks, such as pass the ticket, Public Key Cryptography for Initial Authentication (PKINIT), Shadow Credentials or Active Directory Certificate Services...
blog.zsec.uk
Weekends are for random projects Here is a blog post all around Kerberos errors and a bonus interactive app built in collaboration with @thecontractor.io Errorism Index for Kerberos blog.zsec.uk/common-tool-... kerberos.errorism.io
Common Tool Errors - Kerberos
So you are performing your favourite kerberos attacks, such as pass the ticket, Public Key Cryptography for Initial Authentication (PKINIT), Shadow Credentials or Active Directory Certificate Services...
blog.zsec.uk
Should probably start writing my talk then
First round of talk emails have just gone out. We had over 40 submissions for 18 slots so unfortunately have had to reject over half of them. If you haven't had an email yet, please hang on, more will be sent out shortly as we finalise other things.
First round of talk emails have just gone out. We had over 40 submissions for 18 slots so unfortunately have had to reject over half of them. If you haven't had an email yet, please hang on, more will be sent out shortly as we finalise other things.