badsectorlabs Profile Banner
Bad Sector Labs Profile
Bad Sector Labs

@badsectorlabs

Followers
8K
Following
699
Media
72
Statuses
946

Cybersecurity news, techniques, exploits, and tools every week at https://t.co/UgKmeEEjIV 🐘 @[email protected]

Joined November 2011
Don't wanna be here? Send us removal request.
@badsectorlabs
Bad Sector Labs
2 years
Stop testing in prod (even someone else's)! Are you tired of installing Active Directory on your test VMs for the 100th time? Ever YOLO a binary off GitHub into prod because your testing setup is tedious? I've built a solution: https://t.co/HvzjwZLiwr (1/5)
Tweet card summary image
ludus.cloud
The easiest way to deploy cybersecurity infrastructure
13
74
191
@badsectorlabs
Bad Sector Labs
2 days
Thanks to the community for sharing your work! Follow along @badsectorlabs @lastweekinfosec, 🦋 (@ badsectorlabs. com), 🐘 (@ badsectorlabs.@ infosec. exchange) sign up for the email newsletter at https://t.co/xdz8iguwPR or subscribe to the RSS feed at
0
0
11
@altcoindesknews
Altcoin Desk
16 days
Tired of chasing every new ticker on X? Build a balanced Altcoin portfolio that survives red days too. Checkout how!
0
1
7
@badsectorlabs
Bad Sector Labs
2 days
We published 44 editions of Last Week in Security in 2025, the best technical cybersecurity newsletter. We sifted through the noise (without AI!) to deliver: 📰 179 News Stories 🧠 407 Techniques & Write-ups 🛠️ 438 Tools & Exploits 👀 51 New X Accounts & 37 New Blogs followed
3
8
58
@badsectorlabs
Bad Sector Labs
9 days
This edition is full of solid write-ups and tools!
@lastweekinfosec
Last Week in Security (LWiS)
9 days
SCOM lab (@synzack21), WatchGuard RCE (@_mccaulay), Clickjacking with SVGs (@rebane2001), macOS LPE (@theevilbit), and more!
0
0
9
@SpecterOps
SpecterOps
9 days
SCOM is one of the most deployed, but least researched, System Center products. @synzack21 breaks down how it works + how to build a lab to test new tradecraft.
Tweet card summary image
specterops.io
Yet another System Center Ludus configuration for your collection. https://github.com/Synzack/ludus_scom
1
46
103
@badsectorlabs
Bad Sector Labs
12 days
Beyviel David and BloodHound🤝 Ludus If you're at BHEU, this will be a good one!
@SpecterOps
SpecterOps
14 days
Generic AD labs don’t cut it. Stop by @bagelByt3s' #BHEU Arsenal session and hear about LudusHound, a tool that rebuilds real-world AD environments using actual BloodHound data. Learn more 👉 https://t.co/HyDGactVVq
0
5
17
@mtarral
Mathieu Tarral
15 days
🚀 OSWatcher v0.3 1⃣ Explore Windows evolution from Win95 ➡️ Win11-24H2 (with updates !) 2⃣ Registry explorer File download is disabled, for obvious reasons. ⭐ Feedback welcome! ➡️ https://t.co/PeWLVBR60x
@mtarral
Mathieu Tarral
25 days
🚀 OSWatcher v0.2 ✨ Real git log graph for OS snapshots ⚡ Live filesystem search with streaming results Demo: Search "systemd" across 20 years of Ubuntu history and watch 779 results stream in real-time 👇 ➡️ https://t.co/PeWLVBR60x 👉 Use "CTRL+K" as shortcut
3
8
25
@badsectorlabs
Bad Sector Labs
23 days
Some great answers in this AMA but this is my favorite ☺️
@TrustedSec
TrustedSec
24 days
Our Targeted Operations experts @curi0usJack, @oddvarmoe, @jarsnah12, and @GuhnooPlusLinux are live on #Reddit right now for an AMA! Ask your questions, get pro-level answers. Join the conversation now! https://t.co/bsRwMbR7H7
1
2
40
@M4yFly
Mayfly
29 days
🚀 Introducing MoxPack: A template builder for Proxmox using Packer. Generate Windows & Linux VM templates with cloud-init support and sysprep. Ideal for lab automation and infra-as-code. https://t.co/ewTGY6NqIU
Tweet card summary image
github.com
A Qemu Proxmox Template builder project using Packer - Orange-Cyberdefense/moxpack
0
33
130
@mpgn_x64
mpgn
1 month
Thrilled to share that the Star Wars NetExec lab I made for @_leHACK_ was fully automated by @LadhaAleem on Ludus/VWmare/VirtualBox🔥 Awesome lab with 2AD (rebels&empire), certificats, MSSQL trust, pre2k, and ofc gMSA 👾 Can you find the spy ? GitHub ➡️
Tweet card summary image
github.com
Lab used for workshop and CTF. Contribute to Pennyw0rth/NetExec-Lab development by creating an account on GitHub.
3
81
298
@Golgothus
Golgothus (Zach He/Him)
1 month
When will I learn how to edit / compile my own Terraform / Ansible files 🥲 I love https://t.co/XjIUa3jAQA, it's so freaking dope. My limited small brain knowledge is what limits its potential.
0
1
3
@unsigned_sh0rt
Garrett
2 months
Ludus is so useful and makes it easy to just deploy infra for whatever random shower thought I have. But it's gotten to the point that I need asset management for my lab environments.
3
3
47
@badsectorlabs
Bad Sector Labs
3 months
I set up a new flare VM today (fully automated via Ludus of course) and noticed the new wallpaper indicator for internet status. I wonder if Ludus' red/green wallpaper indicators for network connectivity inspired it @anamma_06? Either way, awesome!
0
5
83
@badsectorlabs
Bad Sector Labs
3 months
Wow. 51 individual tools and a cross platform library to do all things SMB2, MSRPC, and "Security." Now that's a drop! 👏
@codewhisperer84
codewhisperer84
3 months
Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM. https://t.co/GC5wA2y3EO
0
1
28
@badsectorlabs
Bad Sector Labs
3 months
Constructing Defense lab - automated and on your own hardware. That's the power of https://t.co/1HabXkpoGf and the community! It sets up: - Windows events - ADCS Events - Sysmon - Linux telemtry with auditd - K8s audit logging - Full packet capture Awesome work @Antonlovesdnb
Tweet card summary image
ludus.cloud
The easiest way to deploy cybersecurity infrastructure
@Antonlovesdnb
Anton
3 months
HUGE quality of life update is now live for folks who have purchased Constructing Defense! The Ludus lab build is now fully automated and deploys all the components in the lab with just one command! In addition to this update, I have a little surprise as well... You can now
0
6
35
@badsectorlabs
Bad Sector Labs
3 months
Most impactful vulnerability since EternalBlue and you can make the argument that it's actually more impactful as you don't need network access to machines to use it, just hit the cloud API. We are lucky Dirk-jan fights for the users. 🫡
@_dirkjan
Dirk-jan
3 months
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
2
4
78
@badsectorlabs
Bad Sector Labs
3 months
Sure, a bunch of NPM packages got backdoor'd (again), but don't miss the great research and tools released last week!
Tweet card summary image
blog.badsectorlabs.com
Metamorphic compilation (@tijme), Windows Secure Calls (@33y0re), macOS race condition exploit (@patch1t), NTLM relaying (@elad_shamir), iOS zero-click RE (@quarkslab), and more!
0
1
7
@badsectorlabs
Bad Sector Labs
3 months
Compile C code to PIC (shellcode, BOF, or exe) without a reflective loader where every compile produces unique, functional shellcode?
@tijme
Tijme Gommers
3 months
Exciting times. I'm publishing Dittobytes today after presenting it at @OrangeCon_nl ! Dittobytes is a true metamorphic cross-compiler aimed at evasion. Use Dittobytes to compile your malware. Each compilation produces unique, functional shellcode. https://t.co/761G96JDF1
0
1
17
@badsectorlabs
Bad Sector Labs
4 months
Never gets old when you're reading a great new technical blog post, and you see https://t.co/SFqewEhKSU wallpaper in the screenshots. It seems Ludus has quite the foothold at SpecterOps☺️ https://t.co/QcePoj5wuK
Tweet card summary image
specterops.io
Explore how cookie theft has evolved in Chromium browsers with the shift from DPAPI to App-Bound encryption. This post breaks down modern cookie stealing techniques via COM, remote debugging, and...
2
3
30