T3chFalcon Profile Banner
IT Guy Profile
IT Guy

@T3chFalcon

Followers
14K
Following
14K
Media
271
Statuses
4K

Offensive Security Engineer

Navigating Digital Labyrinth
Joined November 2022
Don't wanna be here? Send us removal request.
@T3chFalcon
IT Guy
5 months
Simulated a Chollima-style npm backdoor based on @S3N4T0R_0X0 PoC. The moment npm install runs… you're compromised. Defender? Silent. Victim? Distracted by a fake frontend challenge. Breakdown: https://t.co/nPF8gu18Ya #MalDev #RedTeam #APT
8
11
53
@T3chFalcon
IT Guy
2 hours
Should I ? πŸ˜…
@JohnCak51565137
John Cake
12 hours
@T3chFalcon Can you stop making these tweets please? They're making me feel uncomfortable.
7
0
13
@T3chFalcon
IT Guy
12 hours
It’s nearly impossible to scrub them all surgically without breaking the OS. Windows is a diary that writes in permanent marker.
13
22
213
@T3chFalcon
IT Guy
14 hours
Here's something wild: Your laptop knows exactly how much data every single app has sent to the internet. It’s called the System Resource Usage Monitor (SRUM). Windows logs the network usage of every process for the last 30-60 days to a database (SRUDB.dat). Forensics teams
23
149
1K
@T3chFalcon
IT Guy
23 hours
Did You Know? Uninstalling an app doesn't delete the proof that you ran it. Windows keeps a Ghost File for every program you execute to speed up loading times. It’s called Prefetch. Located in C:\Windows\Prefetch, these .pf files log: The exact Date & Time you ran it. The
69
622
4K
@T3chFalcon
IT Guy
1 day
Shellbags. Interesting..
5
1
31
@T3chFalcon
IT Guy
2 days
Phew!
2
1
22
@T3chFalcon
IT Guy
2 days
Hi πŸ™‚
8
1
27
@T3chFalcon
IT Guy
2 days
11.5k? 😳 But we're still celebrating 10k πŸ˜‚πŸ˜­β€οΈ
@T3chFalcon
IT Guy
3 days
I remember when getting to 1000 followers felt impossible. Today, we are a community of 10,000. Thank you for trusting me with your timeline. πŸ™ For those I haven't met yet: I'm @T3chFalcon, a Red Teamer obsessed with Offensive Security & Tradecraft. I spend my days simulating
5
1
46
@T3chFalcon
IT Guy
2 days
The rabbit hole has no bottom. Once you start looking for the tracking mechanisms, you realize everything is designed to leave a breadcrumb.
23
66
578
@T3chFalcon
IT Guy
2 days
Hollywood lied to you about "Ransom Notes." You think printing a letter keeps you anonymous? It doesn't. Your printer is a snitch. Almost every color laser printer secretly embeds invisible yellow dots on the page called the Machine Identification Code (MIC). It encodes:
@T3chFalcon
IT Guy
5 days
The Printer Dots.
405
2K
15K
@T3chFalcon
IT Guy
3 days
NO. We're just getting started πŸ˜‚πŸ™‚
@0xVelii
Velii
3 days
Bro let’s just β€œfeel” safe please 😭😭
5
0
53
@T3chFalcon
IT Guy
3 days
You think running "Portable Chrome" or "Hacker Tools" from a USB drive keeps you invisible. It doesn't. The second you plug that drive in, Windows logs the Volume Serial Number to the Registry. When the Forensice analyst (or Feds) audit that machine, they see: Device
113
274
3K
@T3chFalcon
IT Guy
3 days
I remember when getting to 1000 followers felt impossible. Today, we are a community of 10,000. Thank you for trusting me with your timeline. πŸ™ For those I haven't met yet: I'm @T3chFalcon, a Red Teamer obsessed with Offensive Security & Tradecraft. I spend my days simulating
19
8
253
@T3chFalcon
IT Guy
3 days
πŸ™‚β€β†”οΈ
@cyber_rekk
Mololuwa | Cybersecurity - (The God Complex)
3 days
Cybersecurity Guys please quote with your Spotify wrapped I wanna see your music taste
0
4
49
@T3chFalcon
IT Guy
3 days
Bro had to send me a mail πŸ˜‚πŸ˜­πŸ˜­ Why Phones Are Worse 1. The "Cloud Sync" Nightmare Your laptop keeps the WiFi list on its hard drive. Your phone syncs it to the Cloud. Apple: Syncs via iCloud Keychain. Android: Syncs via Google Backup. Even if you smash your phone with a
@T3chFalcon
IT Guy
4 days
You probably weren’t told this, but… Your laptop is keeping a travel diary of everywhere you have been for the last 5 years. It’s called WLAN-AutoConfig. Every time you connect to WiFi, Windows logs: SSID (the network name) BSSID (the router’s MAC) Timestamp of the connection
18
41
243
@T3chFalcon
IT Guy
3 days
Hi
11
0
28
@T3chFalcon
IT Guy
4 days
@T3chFalcon
IT Guy
4 days
Congrats. Instead of a hidden binary Registry key, your 'evidence' is stored in a plain text file. var/log/syslog var/lib/NetworkManager .bash_history Forensics teams love you guys. They don't even need a hex editor to read your life. They just use cat. πŸ’€
0
3
80
@T3chFalcon
IT Guy
4 days
Congrats. Instead of a hidden binary Registry key, your 'evidence' is stored in a plain text file. var/log/syslog var/lib/NetworkManager .bash_history Forensics teams love you guys. They don't even need a hex editor to read your life. They just use cat. πŸ’€
@DennisCabooter
Dennis
4 days
@T3chFalcon I use Linux.
80
92
1K
@T3chFalcon
IT Guy
4 days
@T3chFalcon
IT Guy
4 days
Open Command Prompt (Admin) and run: netsh wlan delete profile name=* That wipes it clean. But unless you script that to run on shutdown, the diary starts writing again tomorrow. πŸ’€
4
15
165
@T3chFalcon
IT Guy
4 days
Open Command Prompt (Admin) and run: netsh wlan delete profile name=* That wipes it clean. But unless you script that to run on shutdown, the diary starts writing again tomorrow. πŸ’€
@KwasiTunTum
KwasiTunTum
4 days
How do I clear it?
13
53
495