r1cksec
r1cksec@infosec.exchange
<p>Data breach revealed,<br />Malware lurks, silent, stealthy -<br />OSINT tracks the thread.</p><p>URLs I post may contain malware – be careful and check yourself before running anything.</p>
Posts
-
Post #4494936
LOLRMM is a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors. https://lolrmm.io #infosec #cybersecurity #redteam #pentest
-
Post #4443396
ANIMO is a comprehensive Azure AD / Entra ID assessment platform that combines PowerShell-based session management, Azure CLI parity, and native Graph / ARM API integration. https://github.com/dmcxblue/ANIMO #infosec #cybersecurity #redteam #pentest #cloud #opensource
-
Post #4411117
An MCP server that lets an AI agent drive NetExec (nxc) for authorized security testing only. https://github.com/mpgn/NetExec-mcp #infosec #cybersecurity #pentest #ai
-
Post #4370033
Windows Provisioning Package (.ppkg) generator. Payload runs as SYSTEM on apply. https://github.com/init1Security/PPKGPacker #infosec #cybersecurity #redteam #pentest
-
Post #4346678
A litterbox integration for the Mythic Command and Control Server https://github.com/Whispergate/Sphinx #infosec #cybersecurity #redteam #pentest
-
Post #4269891
Notes on Windows Component Object Model (COM hijacking, elevation of privilege, DCOM lateral movement, and persistence). Notes were generated by Kimi K3 Swarm may contain inaccuracies. https://github.com/An0nUD4Y/Offensive-COM #infosec #cybersecurity #redteam #pentest #windows
-
Post #4193751
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment. https://github.com/Kritt-ai/open-kritt #infosec #ycbersecurity #redteam #pentest #ai
-
Post #4144147
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. https://github.com/haxxm0nkey/credshound #infosec #cybersecurity #redteam #pentest #opensource
-
Post #4108977
Extract Windows credentials directly from VM memory snapshots and virtual disks https://github.com/nikaiw/VMkatz #infosec #cybersecurity #redteam #pentest #opensource
-
Post #4084850
There is a documented enforcement gap in Conditional Access policies that apply to "all resources" but have an exclusion for at least one resource. https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusio #infosec #cybersecurity #redteam #pentest #cloud
-
Post #4058100
This is a proof-of-concept tool to demonstrace CVE-2026-54121 a.k.a Certighost. https://github.com/aniqfakhrul/CVE-2026-54121 #infosec #cybersecurity #redteam #pentest
-
Post #4057850
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. https://github.com/haxxm0nkey/credshound #infosec #cybersecurity #redteam #pentest #opensource
-
Post #3908315
A post about Git integrations that can be used to exploit insecure implementations. https://nopnop.pro/2026/06/17/exploiting-git-integrations-in-cloud-services/ #infosec #cybersecurity #redteam #pentest
-
Post #3887731
This blogpost explains how GPOs work and how filters can be applied in order to restrict their impact. https://www.intrinsec.com/hide-the-threat-gpo-lateral-movement/ #infosec #cybersecurity #redteam #pentest
-
Post #3741961
Entra ID user enumeration and auth method discovery via the public GetCredentialType API https://github.com/RedByte1337/CredSpy #infosec #cybersecurity #redteam #pentest #opensource #cloud
-
Post #3710922
Noma Labs discovered a prompt injection vulnerability within GitHubs new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/ #infosec #cybersecurity #redteam #pentest
-
Post #3666476
A post about the security implications of new features in SQL Server 2025 https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-mssql-2025 #infosec #cybersecurity #redteam #pentest
-
Post #3621180
A post that uses the Windows source code to illustrate several examples of how attackers can customize their indicators of compromise. https://www.abdulmhsblog.com/posts/useingthewindowssourcecode #infosec #cybersecurity #redteam #pentest
-
Post #3428582
RelayKing is a comprehensive relay detection and enumeration tool designed to identify relay attack opportunities in Active Directory environments. https://github.com/depthsecurity/RelayKing-Depth #infosec #cybersecurity #redteam #pentest #opensource
-
Post #2023321
A post about how to use Page Guard Exceptions to bypass AMSI https://shigshag.com/blog/amsi_page_guard #infosec #cybersecurity #redteam #pentest #windows
-
Post #1560423
When Windows Defender realizes that a malicious file has a cloud tag it rewrites the file to it&#39;s original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges. https://github.com/Nightmare-Eclipse/RedSun #infosec #cybersecurity #pentest #windows
-
Post #766460
It is possible as a low privileged user to parse the Windows event logs for any ASR exclusion https://primusinterp.com/posts/WindowsASR/ #infosec #cybersecurity #redteam #pentest
-
Post #433811
A new ClickFix variant dubbed &quot;CrashFix&quot; that intentionally crashes the browser then baits users into running malicious commands https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke #infosec #cybersecurity #threatintel #phishing #malware #redteam