tgindex

Pentester

описание

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

3 074
подписчиков
Охват к подписчикам
49,9%
ERR
Реакции к просмотрам
0,30%
127 на 27 постов
Пересылки к просмотрам
0,54%
223
Постов в день
0,0
всего 27

Где отзываются чаще

доля реакций к просмотрам
  • 22 июл.Offensive AI Agents Landscape: Projects, Models, Skills, MCP Servers, Papers, Benchmarks & Commercial Solutions https://github.com/Yeti-791/Awesome-Offensive-AI-Agentic-Landscape0,89%
  • 25 авг. 2024 г.#redteam Cobalt Strike - CDN / Reverse Proxy Setup https://redops.at/en/blog/cobalt-strike-cdn-reverse-proxy-setup0,81%
  • 17 нояб. 2024 г.#Fortinet FortiManager Unauthenticated RCE (CVE-2024-47575) The remote code execution vulnerability in FortiManager allows attackers to perform arbitrary operations by exploiting commands via the FGFM protocol, circumventing authentication. Referred to as FortiJump, this vulnerability provides unauthorized access to FortiManager, enabling control over FortiGate devices by taking advantage of insufficient security in command handling and device registration processes. Affected Versions: FortiManager 7.6.0 FortiManager 7.4.0 through 7.4.4 FortiManager 7.2.0 through 7.2.7 FortiManager 7.0.0 through 7.0.12 FortiManager 6.4.0 through 6.4.14 FortiManager 6.2.0 through 6.2.12 FortiManager Cloud 7.4.1 through 7.4.4 FortiManager Cloud 7.2.1 through 7.2.7 FortiManager Cloud 7.0.1 through 7.0.12 FortiManager Cloud 6.4 Research: https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/ Source: https://github.com/watchtowrlabs/Fortijump-Exploit-CVE-2024-475750,63%
  • 24 янв.2026-24061: Telnetd RCE as Root This flaw allows an attacker to establish a Telnet session without providing valid credentials, granting unauthorized access to the target system. The vulnerability exists all the way up to version 2.7-2 of the GNU telnetd service. Exploit: https://github.com/SafeBreach-Labs/CVE-2026-24061 Query: ZoomEye: app="GNU Inetutils telnetd" Shodan: product:"telnetd" @news4hack0,57%
  • 17 мар.VMkatz Without VMkatz, the traditional workflow looks like this: exfiltrate the entire VM disk or memory snapshot, mount it locally, install a full Windows analysis stack, load the snapshot into a debugger or use mimikatz on a booted copy, and manually piece together credentials from each VM - one at a time. Multiply that by a dozen VMs on the cluster and you are looking at days of bandwidth, tooling, and post-processing. VMkatz exists because you shouldn't have to exfiltrate what you can read in place. It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor, wherever the VM files are.0,48%
  • 8 июл.T3MP3ST A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter. Point it at an authorized target and the kill chain runs itself: recon → exploit → report, from a browser War Room or the CLI, driven by the agent you're already signed into — Claude Code, Codex, Hermes — or a model you run fully offline (Ollama, LM Studio, vLLM). No new API keys, no cloud tenant, no second bill. Your agent is the brain; T3MP3ST is the war machine bolted around it. Self-hosted storm. Keyless warfare.0,45%
  • 6 янв.Chronomaly — Android / Linux Kernel LPE exploit (CVE-2025-38352) The exploit was written specifically for Linux kernel v5.10.157, but should work against all vulnerable v5.10.x kernels, as it does not require any specific kernel text offsets to work. Blog: • Part 1 - In-the-wild Android Kernel Vulnerability Analysis + PoC • Part 2 - Extending The Race Window Without a Kernel Patch • Part 3 - Uncovering Chronomaly0,45%
  • 21 февр.The Mimikatz Missing Manual My goal was to create the "Missing Manual" — the documentation that explains not just the commands, but the why and the how of the Windows protocols being manipulated. Parts: • Foundations: Setting up your environment and the basic syntax. • System Internals: How Windows handles tokens, processes, and services. • LSASS & Credentials: The heart of Mimikatz—extracting secrets from memory. • Kerberos Deep Dive: Tickets, forgery, and delegation. • PKI & Certificates: Hardware and software-based identities. • Domain Persistence: Owning the directory through replication. •DPAPI: Unlocking the secrets at rest.0,43%
  • 23 февр.Gaining Initial Access and Outsmarting SmartScreen .zip email attachment that includes a VHDX (Hard Disk Image File) + Mark of the Web and SmartScreen bypass using Trusted Executable Reputation and DLL Sideloading. Tools: https://github.com/g3tsyst3m/CodefromBlog/tree/main/2026-2-21-Initial%20Access%20and%20Outsmarting%20SmartScreen0,39%
  • 9 янв.Strix Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proof-of-concepts. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools. Key Capabilities: 🔧 Full hacker toolkit out of the box 🤝 Teams of agents that collaborate and scale ✅ Real validation with PoCs, not false positives 💻 Developer‑first CLI with actionable reports 🔄 Auto‑fix & reporting to accelerate remediation 🎯 Use Cases Application Security Testing - Detect and validate critical vulnerabilities in your applications Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production @news4hack0,39%
  • 22 июл. 2025 г.CVE-2025-53770: SharePoint RCE (ToolShell) Exploit: https://github.com/soltanali0/CVE-2025-53770-Exploit Patched: July 20, 2025 #rce #pentest #redteam #ad #sharepoint #cve0,32%
  • 23 мар.CVE-2026-24291: Windows LPE (RegPwn) Exploit: https://github.com/mdsecactivebreach/RegPwn Blog: https://www.mdsec.co.uk/2026/03/rip-regpwn/ BOF: https://github.com/Flangvik/RegPwnBOF Tested versions: Windows 11 25h2 Windows 11 24h2 Windows 10 21h2 Windows Servers 2016/2019/2022 Patched: Mar 10, 20260,31%