iamchaossec Profile Banner
vadersec Profile
vadersec

@iamchaossec

Followers
23
Following
6
Media
0
Statuses
67

22 |not human at all

the abyssal nightmare realm
Joined July 2024
Don't wanna be here? Send us removal request.
@aacle_
Abhishek Meena 🏡️
15 days
Stop looking for id=1. Start looking for the logic flaws scanners miss. πŸ›‘ Basic IDORs are dying. Modern apps use GUIDs (550e8400-e29b...) to hide data. But obscurity isn't security. Here is the blueprint for finding Advanced Broken Access Control in 2025. πŸ§΅πŸ‘‡ #bugbountytips
4
24
175
@SpecterOps
SpecterOps
2 months
Credential Guard was supposed to end credential dumping. It didn't. @bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ‡️
Tweet card summary image
specterops.io
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
4
308
658
@nsg650
NSG650
2 months
Just put the malware in the bag bro
0
1
15
@emeraldappul
emmie. πŸŽ„πŸΉβ„οΈ
2 months
@MurdoinkGS
Green Screen Videos by Murdoink
2 months
Charlie "yo guys this is me, Charlie" Smiling Friends s03e01 green screen
45
7K
57K
@codewhisperer84
codewhisperer84
3 months
Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM. https://t.co/GC5wA2y3EO
Tweet card summary image
github.com
Windows protocol library, including SMB and RPC implementations, among others. - trustedsec/Titanis
14
187
557
@Print3M_
Print3M
4 months
DLL Sideloading for Initial Access – Red Team Operator's Guide πŸ”₯ (new article) https://t.co/rXWXasjEQs - finding software to backdoor - finding DLL and function to backdoor - legit software backdooring - OPSEC considerations #redteam #infosec #malware #security
1
98
340
@theXSSrat
The XSS Rat - Proud XSS N00b :-)
4 months
πŸ€πŸ’₯ Just dropped a monster stash of wordlists for bounty hunters. We’re talking: βš”οΈ Subdomains to slice attack surface πŸ”‘ Creds & API keys for low-hanging wins πŸ’‰ Payloads (XSS/SQLi/SSRF/LFI/RCE) to pop boxes πŸ“‚ Directories & APIs no admin wants you to see Basically… your
drive.google.com
2
10
35
@MalDevAcademy
MalDev Academy
4 months
TrapFlagForSyscalling - Evading userland hooks through indirect tampered syscalls with the Trap Flag. https://t.co/raJjbzKyos
Tweet card summary image
github.com
Bypass user-land hooks by syscall tampering via the Trap Flag - Maldev-Academy/TrapFlagForSyscalling
0
46
248
@0xLegacyy
Jord
4 months
gdbw v0.1.0 releasing tomorrow! 🐸 Still a lot to add but hoping to get it into user's hands sooner so that we can figure out pain points etc.
6
4
63
@i7z00_
i7z00
4 months
when looking for cache deception bugs remember to brute force delimiters in all endpoints returning sensitive data, In a recent target I found three endpoints Vulnerable to cache deception with Different delimiters, also try: /endpoint$delimeter$.js /endpoints/$delimeter$.js
3
21
211
@ipurple
Panos Gkatziroulis πŸ¦„
5 months
Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls
Tweet card summary image
github.com
Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls. - MatheuZSecurity/RingReaper
0
18
94
@GrahamHelton3
Graham Helton (too much for zblock)
5 months
This new @SpecterOps paper fills me with so much joy
4
80
395
@nostarch
No Starch Press
5 months
Most red team books tell you WHAT to do. This one shows you HOW to actually do it. Red Team Engineering by @CaseyLErdmann breaks the "theory only" curse – custom tools, real infrastructure, the techniques that usually stay behind closed doors. From someone who's actually been
12
187
1K
@0xfluxsec
flux
5 months
Introducing: Hells Hollow - Thought rootkit SSDT hooking was dead? Following my previous work, I have managed to essentially reintroduce SSDT hooks, capable of modifying the *original* KTRAP_FRAME and more! Whitepaper: https://t.co/eFDLsey9Av #infosec #cybersecurity
5
96
350
@IroncladDev
IroncladDev
5 months
9
35
655
@OrdinaryGamers
Mutahar
7 months
No fucking way lol
@SwitchTools
SwitchTools
7 months
First userland ropchain exploit on the Switch 2 Source: https://t.co/gLAAycocwX
172
552
17K
@0xor0ne
0xor0ne
8 months
Process injection in Linux (beginners introduction) https://t.co/F5PYrXaJo3 #infosec #linux
0
49
335
@elder_plinius
Pliny the Liberator πŸ‰σ …«σ „Όσ „Ώσ …†σ „΅σ „σ …€σ „Όσ „Ήσ „Ύσ …‰σ …­
8 months
we are literally at "jailbreak yourself" rofl
65
141
3K
@_bergee_
bergee
11 months
I hacked NASA for fun and !profit :) #BugBounty @NASA @Bugcrowd
5
4
69