LOLRMM is a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors.
https://lolrmm.io
#infosec #cybersecurity #redteam #pentest
ANIMO is a comprehensive Azure AD / Entra ID assessment platform that combines PowerShell-based session management, Azure CLI parity, and native Graph / ARM API integration.
https://github.com/dmcxblue/ANIMO
#infosec #cybersecurity #redteam #pentest #cloud #opensource
kingthorin_rm
@kingthorin_rm@infosec.exchange
IT Sec guy, zaproxy co-lead, OWASP WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
infosec.exchange
What's this? @zaproxy@infosec.exchange fuzzer update released this morning, with work from yours truly.
#PenTest #WebAppSec #BugBountyTips
An MCP server that lets an AI agent drive NetExec (nxc) for authorized security testing only.
https://github.com/mpgn/NetExec-mcp
#infosec #cybersecurity #pentest #ai
Windows Provisioning Package (.ppkg) generator. Payload runs as SYSTEM on apply.
https://github.com/init1Security/PPKGPacker
#infosec #cybersecurity #redteam #pentest
A litterbox integration for the Mythic Command and Control Server
https://github.com/Whispergate/Sphinx
#infosec #cybersecurity #redteam #pentest
Notes on Windows Component Object Model (COM hijacking, elevation of privilege, DCOM lateral movement, and persistence). Notes were generated by Kimi K3 Swarm may contain inaccuracies.
https://github.com/An0nUD4Y/Offensive-COM
#infosec #cybersecurity #redteam #pentest #windows
Chema Alonso
@chemaalonso@ioc.exchange
Cuenta de Chema Alonso. Opiniones son personales. Mi e-mail público es http://mypublicinbox.com/ChemaAlonso
ioc.exchange
El lado del mal - Bootcamp de Ciberseguridad Defensiva y Ofensiva en HackBySecurity https://www.elladodelmal.com/2026/07/bootcamp-de-ciberseguridad-defensiva-y.html #BootCamp #Ciberseguridad #Pentest #Pentesting #0xWord #MyPublicInbox #Online
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.
https://github.com/Kritt-ai/open-kritt
#infosec #ycbersecurity #redteam #pentest #ai
BSidesLuxembourg
@BSidesLuxembourg@infosec.exchange
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
infosec.exchange
💻 𝗧𝗛𝗢𝗦𝗘 𝗪𝗛𝗢 𝗗𝗢𝗡’𝗧 𝗟𝗘𝗔𝗥𝗡 𝗙𝗥𝗢𝗠 𝗖𝗩𝗘𝗦 𝗔𝗥𝗘 𝗗𝗢𝗢𝗠𝗘𝗗 𝗧𝗢 𝗥𝗘𝗗𝗜𝗦𝗖𝗢𝗩𝗘𝗥 𝗧𝗛𝗘𝗠 💥 - Louis Nyffenegger
https://archive.org/details/BSidesLuxembourg2026/d1+t1+10+Those+Who+Don%E2%80%99t+Learn+From+CVEs+Are+Doomed+To+Rediscover+Them+-+Louis+Nyffenegger.mkv
Watch Louis Nyffenegger's ( @snyff@infosec.exchange ) session, recorded live at the Digital Learning Hub during BSides Luxembourg 2026.
#BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
https://github.com/haxxm0nkey/credshound
#infosec #cybersecurity #redteam #pentest #opensource
Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
#infosec #cybersecurity #redteam #pentest #opensource
There is a documented enforcement gap in Conditional Access policies that apply to "all resources" but have an exclusion for at least one resource.
https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusio
#infosec #cybersecurity #redteam #pentest #cloud
This is a proof-of-concept tool to demonstrace CVE-2026-54121 a.k.a Certighost.
https://github.com/aniqfakhrul/CVE-2026-54121
#infosec #cybersecurity #redteam #pentest
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
https://github.com/haxxm0nkey/credshound
#infosec #cybersecurity #redteam #pentest #opensource
A post about Git integrations that can be used to exploit insecure implementations.
https://nopnop.pro/2026/06/17/exploiting-git-integrations-in-cloud-services/
#infosec #cybersecurity #redteam #pentest
This blogpost explains how GPOs work and how filters can be applied in order to restrict their impact.
https://www.intrinsec.com/hide-the-threat-gpo-lateral-movement/
#infosec #cybersecurity #redteam #pentest
Chema Alonso
@chemaalonso@ioc.exchange
Cuenta de Chema Alonso. Opiniones son personales. Mi e-mail público es http://mypublicinbox.com/ChemaAlonso
ioc.exchange
El lado del mal - The Art of Pentesting (English Edition) en Amazon https://www.elladodelmal.com/2026/07/the-art-of-pentesting-english-edition.html #Pentest #Pentesting #Hacking #book #Cybersecurity #AMAZON #Kindle #ePub #0xWord
Entra ID user enumeration and auth method discovery via the public GetCredentialType API
https://github.com/RedByte1337/CredSpy
#infosec #cybersecurity #redteam #pentest #opensource #cloud
Noma Labs discovered a prompt injection vulnerability within GitHubs new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
#infosec #cybersecurity #redteam #pentest