codex_tf2 Profile Banner
CodeX Profile
CodeX

@codex_tf2

Followers
2K
Following
479
Media
127
Statuses
930

advanced persistent clown 🤡 📕 redteam blog: https://t.co/ihAv2kG3JR 🛠️ github: https://t.co/VhmOUAWcTp

explorer.exe
Joined February 2022
Don't wanna be here? Send us removal request.
@codex_tf2
CodeX
4 years
[Pin] My maldev link dump if anyone else wants to read :D (Will be updated) https://t.co/Bp0cYuqmRj
1
9
24
@codex_tf2
CodeX
14 days
mfw one of my beacons had the internet speed of a rural village so i had to add options to my screenshot BOF to push file size down💀 update pushed to the repo https://t.co/DYOfJcmLyA
3
8
71
@codex_tf2
CodeX
26 days
Added my ICMP, NTP and Websocket C2 channel examples to the public repo. https://t.co/GLmksKiBY7 Also accompanying blog post explaining the template: https://t.co/3zvoKvUdDl pls no flame bad code :D Websocket channel in action:
3
25
145
@codex_tf2
CodeX
28 days
Added a few more example C2 channels to the Cobalt Strike custom c2 channel template on top of the existing file read/write PoC: - named pipe - TCP - UDP https://t.co/TjJ310AFdE
1
14
98
@codex_tf2
CodeX
29 days
Open sourced my template code for implementing custom C2 channels via a UDRL hook in Cobalt Strike Hopefully this makes developing custom c2 channels for CS easier, because externalC2 spec is a pain. Or just use the upcoming UDC2 interface /shrug https://t.co/GLmksKiBY7
Tweet card summary image
github.com
template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader. - CodeXTF2/CustomC2ChannelTemplate
3
11
77
@codex_tf2
CodeX
1 month
Been using @_RastaMouse 's crystal kit as a UDRL dev template for the past few days and did quite a few cool things, among them was implementing a custom c2 channel template (in this case, PoC using files on disk as the channel) using IAT hooks on the wininet functions
3
16
121
@codex_tf2
CodeX
5 months
mfw hashcat v7 b4 gta6
@hashcat
hashcat
5 months
hashcat v7.0.0 released! After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had. Detailed writeup is available here: https://t.co/fxAIXNXsEr
0
0
7
@C5pider
5pider
6 months
Introducing Havoc Professional: A Lethal Presence We’re excited to share a first look at Havoc Professional, a next-generation, highly modular Command and Control framework, and Kaine-kit our fully Position Independent Code agent engineered for stealth! https://t.co/0aPVihoFIU
Tweet card summary image
infinitycurve.org
An introduction to Havoc Professional and Kaine-kit, exploring the advanced features and capabilities that make them lucrative for modern security professionals.
56
186
745
@codex_tf2
CodeX
6 months
average day as an aggressorscript victim
1
1
24
@C5pider
5pider
6 months
@TheHackersNews ah interesting
5
1
54
@SEKTOR7net
SEKTOR7 Institute
6 months
Swimming deep inside Windows Security Center service to re-engineer API access allowing to disable Windows Defender. COM interface reconstruction and integrity checks bypassed to inform WD that its not the-boss-in-the-house anymore... A post by @es3n1n. Nicely done! Repo:
2
33
138
@trickster012
trickster0
6 months
This is my research project in creating read, write and allocate primitives that can be turned into an injection in order to evade certain telemetry which I presented last year in RedTreat. I hope everyone likes it \m/. https://t.co/GY37MMfCGl
trickster0.github.io
It has been a while, this is my research on trying to change the IOCs of a common remote process injection flow and the end result. I presented this in RedTreat in 2024 and I thought it was about...
6
93
265
@C5pider
5pider
7 months
Truly excited for the upcoming workshop. Covering modern ransomware evasion & detection and also implementing your own ransomware/decryptor for Windows, MacOS and Linux. See you soon! 👻
@rad9800
Rad
7 months
Looking forward to running the ransomware workshop at @x33fcon this week with @C5pider. Some teasers of what to expect, with some painstakingly crafted slides 🙃
7
38
330
@codex_tf2
CodeX
7 months
crto2 pwned pogpogpog https://t.co/YWAcq6iCMB
0
1
18
@kyleavery
Kyle Avery
7 months
So excited to speak at #BHUSA for the first time this year! I'll talk about training LLMs on verifiable tasks (including what exactly that means) with a case study automating some maldev work.
7
6
68
@M_alphaaa
Matt Ehrnschwender
7 months
I'm finally releasing a project that I've been working on for a little while now. Here's Boflink, a linker for Beacon Object Files. https://t.co/herd91NIGF Supporting blog post about it.
blog.cybershenanigans.space
Intro This is a blog post written for a project I recently released. The source code for it can be found here on Github. Background The design of Cobalt Strike’s Beacon Object Files is rather unique...
6
64
206
@_logangoins
Logan Goins
7 months
I'm super happy to announce an operationally weaponized version of @YuG0rd's BadSuccessor in .NET format! With a minimum of "CreateChild" privileges over any OU it allows for automatic escalation to Domain Admin (DA). Enjoy your inline .NET execution! https://t.co/nvZmsNqjnG
Tweet card summary image
github.com
SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai. - logangoins/SharpSuccessor
7
169
438
@rad9800
Rad
7 months
Learn to evade and strengthen security controls by building your own ransomware. For a teaser on what to expect, check out my talk 'Windows Ransomware Detection' https://t.co/a0f2jvPIcr Excited to have y'all join us next month.
@x33fcon
/ˈziːf-kɒn/
7 months
🛠️Join @rad9800 and @C5pider for onsite-only workshop at #x33fcon! Build a fully functional ransomware prototype and uncover the mechanics behind this persistent threat. Learn file encryption, stealth tactics, and how to bypass anti-ransomware tools, with a deep dive into Windows
2
11
59
@codex_tf2
CodeX
7 months
a certain certification vendor must be fuming right now
20
69
1K
@volatility
volatility
7 months
We are very excited to announce that Volatility 3 has reached parity with Volatility 2! With this achievement, Volatility 2 is now deprecated. See the full details in our blog post:
Tweet card summary image
volatilityfoundation.org
Visit the post for more.
3
157
356
@codex_tf2
CodeX
7 months
wtf bro has a larger bounty than john wick 😭
0
0
10