#pentest

26 posts · Last used 3d

Back to Timeline
r1cksec @r1cksec@infosec.exchange · 3d ago
LOLRMM is a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors. https://lolrmm.io #infosec #cybersecurity #redteam #pentest
0
0
0
r1cksec @r1cksec@infosec.exchange · 6d ago
ANIMO is a comprehensive Azure AD / Entra ID assessment platform that combines PowerShell-based session management, Azure CLI parity, and native Graph / ARM API integration. https://github.com/dmcxblue/ANIMO #infosec #cybersecurity #redteam #pentest #cloud #opensource
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 31, 2026
Notes on Windows Component Object Model (COM hijacking, elevation of privilege, DCOM lateral movement, and persistence). Notes were generated by Kimi K3 Swarm may contain inaccuracies. https://github.com/An0nUD4Y/Offensive-COM #infosec #cybersecurity #redteam #pentest #windows
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 29, 2026
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment. https://github.com/Kritt-ai/open-kritt #infosec #ycbersecurity #redteam #pentest #ai
0
0
0
BSidesLuxembourg @BSidesLuxembourg@infosec.exchange · Jul 28, 2026
💻 𝗧𝗛𝗢𝗦𝗘 𝗪𝗛𝗢 𝗗𝗢𝗡’𝗧 𝗟𝗘𝗔𝗥𝗡 𝗙𝗥𝗢𝗠 𝗖𝗩𝗘𝗦 𝗔𝗥𝗘 𝗗𝗢𝗢𝗠𝗘𝗗 𝗧𝗢 𝗥𝗘𝗗𝗜𝗦𝗖𝗢𝗩𝗘𝗥 𝗧𝗛𝗘𝗠 💥 - Louis Nyffenegger https://archive.org/details/BSidesLuxembourg2026/d1+t1+10+Those+Who+Don%E2%80%99t+Learn+From+CVEs+Are+Doomed+To+Rediscover+Them+-+Louis+Nyffenegger.mkv Watch Louis Nyffenegger's ( @snyff@infosec.exchange ) session, recorded live at the Digital Learning Hub during BSides Luxembourg 2026. #BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps
1
0
2
r1cksec @r1cksec@infosec.exchange · Jul 27, 2026
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. https://github.com/haxxm0nkey/credshound #infosec #cybersecurity #redteam #pentest #opensource
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 25, 2026
There is a documented enforcement gap in Conditional Access policies that apply to "all resources" but have an exclusion for at least one resource. https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusio #infosec #cybersecurity #redteam #pentest #cloud
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 24, 2026
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. https://github.com/haxxm0nkey/credshound #infosec #cybersecurity #redteam #pentest #opensource
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 17, 2026
This blogpost explains how GPOs work and how filters can be applied in order to restrict their impact. https://www.intrinsec.com/hide-the-threat-gpo-lateral-movement/ #infosec #cybersecurity #redteam #pentest
0
0
0
r1cksec @r1cksec@infosec.exchange · Jul 10, 2026
Noma Labs discovered a prompt injection vulnerability within GitHubs new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/ #infosec #cybersecurity #redteam #pentest
1
0
2