Constantin @HackmichNet
Windows security novice ... Always try to learn something new ... Happy hacking hackmich.net Joined June 2011-
Tweets4K
-
Followers464
-
Following2K
-
Likes716
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 - Justin Kalnasy - @SpecterOps specterops.io/blog/2026/06/1…
Undocumented IMsiServer COM interface for DCOM upload & execution. A post by Eliran Nissan. Source: deepinstinct.com/blog/forget-ps… #redteam #blueteam
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend. Don't miss this 💪 : semperis.com/blog/identity-…
A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. dirkjanm.io/borrowing-wind… If you do anything with Active Directory, Entra ID, identity security, red teaming, or detection engineering and you're not reading his blog, you're behind. This is the researcher who found CVE-2025-55241, Global Admin in every Entra ID tenant in the world. No logs. No Conditional Access. Microsoft fixed it in 3 days. Creator of ROADtools, ROADrecon, roadtx, krbrelayx, mitm6, and ntlmrelayx contributions. His blog covers: PRT theft and phishing, Conditional Access bypass via resource exclusions, Temporary Access Pass lateral movement, Azure AD Connect credential dumping, Cloud Kerberos Trust abuse from Azure AD to on-prem, AD CS attack surface extended to Intune, SID filtering bypass across forest trusts (CVE-2020-0665), safer Zerologon exploitation, unconstrained Kerberos delegation abuse, ACL privilege escalation, and B2B trust hopping. Every post comes with tools, detection queries, and full attack chains. Bookmark the entire blog. dirkjanm.io Author: @_dirkjan #Infosec #RedTeam #DetectionEngineering
SMBLoot has been updated with: - OPSEC mode: directory trees are cached when opened, preventing new requests when revisiting them; for example, when navigating back to a parent directory. - Sensitive file highlighting: files such as .kdbx, .vhd, .ova, and .bash_history are now easier to spot. - Kerberos authentication support, thanks to a merged PR. - File modification timestamps in the browsing view. Feel free to suggest more features🥰
SMB browsing without the endless use share, cd, and get file commands 😃 SMBLoot lets you navigate with your keyboard, preview files, filter directory listings, and recursively download entire directory trees from a TUI. github.com/swisskyrepo/SM…
I recently updated "The Ultimate WDAC Bypass List" to include TextTransform.exe as well as a few undocumented placeholder entries (despite my personal feelings of seeing some good rainy day bypasses disclosed in an unexpected, lazy fashion). More updates coming soon... github.com/bohops/Ultimat…
ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. ➡️ ghst.ly/3RGyETm Catch @_Mayyhem demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.
Whether we want to admit it or not - the more we connect to our agents, the larger we are making the attack surface. In my @btphantomlabs blog below, I go over how easy it is to impersonate a user (with stolen credentials) through OpenAIs "Apps" (remote MCP servers): beyondtrust.com/blog/entry/cod…
Extracting and analyzing Windows service configurations and ACLs. A tool by Panagiotis Chartas (@t3l3machus) Source: github.com/t3l3machus/ACE… #redteam #blueteam
For anyone who was wondering "how to" regarding to my last two Posts - here is a small writeup and Proof of Concept 🫡🔥
New Blogpost regarding to "Backdooring Open-Weight Models" just published by @ShitSecure: msecops.de/blog/posts/bac…
''Large Workflows with Local LLMs'' #infosec #pentest #redteam #blueteam trustedsec.com/blog/large-wor…
New blog Spent way too much time reverse engineering CrowdStrike Falcon. Somewhere along the way, I found a bug. It's low and not practically exploitable... but a bug is a bug :) Publishing soon 0xdbgman.github.io/posts/inside-t…
CVE-2026-50502: PoC Exploit Public for Event Log RCE - securityonline.info/cve-2026-50502…
Bug Bounty using Claude and Burp Suite yeswehack.com/learn-bug-boun…
An Active Directory security-assessment toolkit in Rust (Scan,Enum,Attack)! 🔥 Amazing work by icedracon! github.com/icedracon/adha…
Our Troopers 26 talk "Modern Adventures in Azure Privilege Escalation" is now online. Thomas and I have an associated blog and resources in the works, so there will be more from us soon. Thanks again to @WEareTROOPERS. This was a fantastic experience! youtube.com/watch?v=GaOi82…
AI agents are becoming a new layer of enterprise identity. They can access data & execute workflows, thus they also create new attack paths. @elad_shamir explores how BloodHound Enterprise extends Attack Path Management to Microsoft Entra Agent ID. ghst.ly/4xbGsM9
I successfully trained a small LLM to always include backdoor code into any answer. All code generated will execute attacker defined commands. And that was 5-10 minutes of work for a PoC wtf? 🫣
If you aren't using herdr for your agents, you are missing out big time. Absolutely destroys tmux, and the integrations on your coding agents with worktrees is a huge level up. Check it out here: herdr.dev Also, ensure to check out the quick start, watch the 6 min video. It shows you how to setup the integration workflow, and the skills setup here: youtube.com/watch?v=qnIu-X… 6 minutes, and completely change your coding experience for the better. Guarantee it. Best shell I have ever used.
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Fabian Bader @fabian_bader
10K Followers 898 Following #Security #Azure #AAD #MDE #M365 #AD #PKI #XDR #EntraID Microsoft MVP Tweets and opinions are my own @[email protected]
Thomas Naunheim @Thomas_Live
7K Followers 462 Following #MicrosoftMVP | Cyber Security Architect 🛡️| #MicrosoftEntra 🔑 + #Azure ☁️ | #Schaengel
Sami Lamppu @samilamppu
3K Followers 820 Following Principal Cloud Security Lead, Elisa Santa Monica, Microsoft Security MVP. Tweets are my own. Blogger, speaker.
Michael Schneider @0x6d69636b
1K Followers 417 Following infosec, working at @scipag, #RedTeam, classic car rally driver for @teampaddymurphy, 🐘@[email protected]
Joe Stocker @ITguySoCal
8K Followers 1K Following Christian Family Man, Founder of Patriot Consulting (Cybersecurity Partner) Author of "Securing Microsoft 365" and Microsoft MVP (Security) (2020-2026).
Enno Rey @Enno_Insinuator
7K Followers 2K Following Old-school network security person. Founded https://t.co/jnQuHO036k & @WEareTROOPERS. Occasionally blogging at https://t.co/67lpbmCajA
zerrin @zerrinkrtas
15 Followers 324 Following
𝚝𝚑𝚎𝚜𝚎�... @T_0_r_nado
60 Followers 5K Following
wh1t3k04l4 @wh1t3k04l4
0 Followers 140 Following
fin3ss3g0d @fin3ss3g0d
221 Followers 65 Following Red Team Operator/Pen Tester | Offensive Security Software Developer | Tweets are unaffiliated with my employer | OSCP | OSEP | CRTO | CRTL
Mstr Omar @omar_mstr40990
0 Followers 20 Following
Senyndo @Senyndo9XN_
79 Followers 3K Following
Karen Hunter @KarenHunte77078
1 Followers 141 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/9dITK81Lgw
Malcolm Stephenie @M__Stephenie
2K Followers 6K Following I Dreams inspires 🗽 I Financial Freedom 💰 | Real Estate 🏡 I Work from Home 🏠 I Digital Entrepreneur 🅱️ I Crypto and Stock Agent 📈
Kylee King @KyleeKing297580
143 Followers 5K Following
Dennis Schäfer @dennsch
1 Followers 113 Following
Toffy @toffyrak
270 Followers 228 Following
Eetwooeeroj @Eetwooeeroj941
27 Followers 1K Following
DriveByte GmbH @drive_byte
29 Followers 93 Following Sleep well again and leave hackers no chance to begin with. We provide innovative and tailored cybersecurity services, for corporate, and SME sized businesses.
TomU | I'm still here... @c_APT_ure
8K Followers 6K Following #InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
Shatra @Shatra51856311
9 Followers 280 Following
perfect4sec @perfect4sec
743 Followers 5K Following DFIR | Threat Intelligence | Malware Analyst | Researcher | Cybersecurity Proactive Defense Team
klm @klmxtom
5 Followers 442 Following
_Ray @_RayRT
619 Followers 896 Following Senior Adversarial Engineer Member of EVILCORP\Domain Fathers https://t.co/SIwC7MLXmP https://t.co/WeF9QBYGcQ
Minh Dang Tuan @tuanminh_eth
33 Followers 1K Following
Marshall @__Mastadon
71 Followers 291 Following
RET2 WarGames @ret2wargames
2K Followers 2K Following Our industry-leading platform is the most effective solution for learning modern binary exploitation through a world-class curriculum developed by @RET2Systems
Carsten @0xcsandker
2K Followers 179 Following Security enthusiast, Likes Windows Internals, AD & Entra — https://t.co/mVVbfkO7IO
Nithin Chenthur Prabh... @Azr43lKn1ght
698 Followers 1K Following Unit 42 | Creator of DFIR Labs | Former Captain @teambi0s | DFIR | Malware Analyst | Maldev | Windows RE | Trounce🦇 | Views My Own
Felix @fr1dlix
1 Followers 148 Following
Hexnov @hexnov
116 Followers 922 Following Interested in offensive security and heavy music 💻🎶 purple teaming & adversary simulation 💜⚔️
test domain @User2Micro
703 Followers 5K Following
'); DROP T̆ͫ̑̒̿�... @fardarter
1K Followers 4K Following It turns out I'm a programmer. Ethnic Jew (not a Zionist). They/them. @[email protected] @fardarter.bsky.social
Sascha Stumpler 💻 @SasStu
1K Followers 735 Following IT Professional working with #MSIntune #M365 #Windows #Entra #PowerShell #Azure #EPM #LeastPrivilege #BeyondTrust #ConfigMgr #CM #OSD
Tony Gore @nullg0re
646 Followers 1K Following Security Researcher, US Marine Corps Veteran, Microsoft Most Valuable Researcher 2023 & 2024
Sen. Sally Eaves @sallyeaves
137K Followers 109K Following Innovating #tech #education #business CEO Tomorrows' Tech Today - CTO CIO Senator Author - #CyberSecurity #AI #5G #TechForGood #SDGs #IoT #ESG #FinTech #STEM
Benjamin Boecker @x01a4
5 Followers 101 Following
cyberkali @cyberkali1
7 Followers 313 Following
Scomnewbie @fanfleon
73 Followers 388 Following
Gerald Gaiswinkler @gaiswige
10 Followers 337 Following
deckerXL @deckerXL
44 Followers 725 Following
James W. @cyberbiz4
162 Followers 4K Following looking for a cyber position in blue team. Metro Vancouver, Canada. Defender, GIAC x 3, AWS, M365, Splunk, Azure
9MF @n1neMF
82 Followers 5K Following
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Oliver Lyak @ly4k_
9K Followers 268 Following Yet another security researcher 🔦 Github: https://t.co/7WFOFz17KI
Florian Roth ⚡️ @cyb3rops
222K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Nathan McNulty @NathanMcNulty
19K Followers 1K Following Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🦋@nathanmcnulty.com
5pider @C5pider
35K Followers 132 Following research & development @InfinityXCurve | personal blog: https://t.co/4gzLz0Z26z
Charlie Bromberg « ... @_nwodtuhs
16K Followers 664 Following Trying to hack the way we hack things 🏴☠️
vx-underground @vxunderground
443K Followers 369 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Dirk-jan @_dirkjan
30K Followers 208 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
Matt Zorich @reprise_99
15K Followers 2K Following @Microsoft Security | https://t.co/HWozKuixTi | Tweets are my own | 🇦🇺
Florian Hansemann @CyberWarship
89K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
Sami Laiho @samilaiho
31K Followers 692 Following Chief Research Officer (opinions are my own) / #1 & #2 at Ignite 2018 / Best Session - NIC x 5 / MVP Windows OS / https://t.co/YcBqnFRmjZ / PluralsightAuthor
Fabian Bader @fabian_bader
10K Followers 898 Following #Security #Azure #AAD #MDE #M365 #AD #PKI #XDR #EntraID Microsoft MVP Tweets and opinions are my own @[email protected]
Thomas Naunheim @Thomas_Live
7K Followers 462 Following #MicrosoftMVP | Cyber Security Architect 🛡️| #MicrosoftEntra 🔑 + #Azure ☁️ | #Schaengel
BleepingComputer @BleepinComputer
256K Followers 205 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Problem solver with a passion for troubleshooting complex issues.
Andrea P @decoder_it
9K Followers 322 Following Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
an0n @an0n_r0
14K Followers 732 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
Keanu Nys @RedByte1337
1K Followers 84 Following Offensive Security Lead @ Spotit. Creator of GraphSpy
International Cyber D... @IntCyberDigest
202K Followers 262 Following Independent reporting on cybersecurity, tech, AI & digital policy.
Pliny the Liberator �... @elder_plinius
232K Followers 1K Following ⊰•-•⦑ latent space steward ❦ prompt incanter 𓃹 hacker of matrices ⊞ breaker of markov chains ☣︎ ai danger researcher ⚔︎ bt6 ⚕︎ architect-healer ⦒•-•⊱
Jiří Vinopal @vinopaljiri
11K Followers 598 Following Security Researcher at @_CPResearch_ All opinions expressed here are mine only. https://t.co/bNWc3k9HwF
Ru Campbell @rucam365
8K Followers 1K Following Microsoft Security MVP • Dad, metal, lifting • Author, MDE in Depth 2nd Ed + Mastering Defender XDR • @Threatscape • @M365SandCUG • https://t.co/CaVgOm9glh
Tim Medin @TimMedin
18K Followers 595 Following Kerberoast Guy • @RedSiege CEO • IANS Faculty • Former SANS SEC560 Author, Senior Instructor • Packers Owner #GoPackGo • Work Req: https://t.co/ALJldLMDfZ
Johann Rehberger @wunderwuzzi23
10K Followers 661 Following Hacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
- @Wh1t3Rh1n0
326 Followers 124 Following
Offensive AI Con @OffensiveAIcon
1K Followers 17 Following Year 2 of the first con dedicated to exploring the offensive use of AI. Hosted by RemoteThreat. Oct 4-7, 2026 | Oceanside, CA #OffensiveAICon
codewhisperer84 @codewhisperer84
524 Followers 44 Following
_leon_jacobs(💥) @leonjza
5K Followers 510 Following ⟦ 'cto @sensepost', '@orangecyberdef', 'caffeine fueled', '(╯°□°)╯︵ ┻━┻', 'security guy', 'metalhead', 'i saw your password', 'KOOBo+KXleKAv+KXlSnjgaM=' ⟧
fin3ss3g0d @fin3ss3g0d
221 Followers 65 Following Red Team Operator/Pen Tester | Offensive Security Software Developer | Tweets are unaffiliated with my employer | OSCP | OSEP | CRTO | CRTL
%TEMP% @TEMP43487580
1K Followers 223 Following Red Team | Beginner @FujitsuOfficial ex @secureworks
ret2src @ret2src
414 Followers 1K Following Breaker of Stuff | Injector of 0x41 | Discoverer of Dumb Things | Creator of Glitches. Dropping shells since 0x7DC.
ʞʞıdɐɔoɥƆ @Chocapikk_
4K Followers 317 Following Security Researcher & Exploit Developer @VulnCheckAI
Cedric Halbronn @saidelike
4K Followers 887 Following AI-Enhanced Security researcher, Pwn2Own {2021, 2022}, #VR #RE #ED #AI (Mastodon: @[email protected])
_Ray @_RayRT
619 Followers 896 Following Senior Adversarial Engineer Member of EVILCORP\Domain Fathers https://t.co/SIwC7MLXmP https://t.co/WeF9QBYGcQ
Simon Skotheimsvik | ... @SSkotheimsvik
1K Followers 442 Following Senior Cloud Consultant @TeamCloudWay | Microsoft MVP | International Speaker | Tech Blogger | https://t.co/53B2rAqsIx | MOD for https://t.co/vs4E6SM6no |
Traceix @usetraceix
18K Followers 405 Following Making file analysis less magical. AI designed to help, not replace you.
Anthony. @AnthonySecurity
2K Followers 2K Following Founder @HiveSecLtd, AI / . / Offensive Security
sapir federovsky @sapirxfed
5K Followers 200 Following Doing things @wiz_io And then doing more things at home | Failed research blog: https://t.co/j2HT1Tpscs | Trying to be more chill🧘♀️
(account is frozen fo... @cj_berlin
616 Followers 0 Following
Nithin Chenthur Prabh... @Azr43lKn1ght
698 Followers 1K Following Unit 42 | Creator of DFIR Labs | Former Captain @teambi0s | DFIR | Malware Analyst | Maldev | Windows RE | Trounce🦇 | Views My Own
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
Hexnov @hexnov
116 Followers 922 Following Interested in offensive security and heavy music 💻🎶 purple teaming & adversary simulation 💜⚔️
Edwin van Andel @Yafsec
5K Followers 2K Following https://t.co/N6FLQyoPB7 • CTO • Speaker • Security • Hacking • ALT-S Organizer • נקר ירוק • Last Unicorn Con • DC672 • DC31 • iamthecavalry • team cheeso
Leo Visser @autosysops
418 Followers 661 Following Cloud Consultant | MVP | MCT | Azure | Security | DevOps | Agile
Christian Ritter MVP @blackboxcoder
803 Followers 925 Following He/Him | Father of two ♥️♥️ | MVP |#PowerShell aficionado | Automation enthusiast | Blog author | Founder of PSUGFFM | Public Speaker | Opinions are my own.
Octoberfest7 @Octoberfest73
9K Followers 192 Following Red Team | Offensive Tool Dev | 2x Course Author @ Zero-Point Security
Aurélien Chalot @Defte_
4K Followers 487 Following Hacker, sysadmin and security researcher @OrangeCyberdef 💻 Calisthenic enthousiast 💪 and wannabe philosopher https://t.co/SqDDhIGGGh 📖 🔥 Hide&Sec 🔥
0xor0ne @0xor0ne
93K Followers 508 Following Cybersecurity | Reverse Engineering | Vulnerability Research | Embedded & Silicon Security | My Tweets, My Opinions :)
Tony Gore @nullg0re
646 Followers 1K Following Security Researcher, US Marine Corps Veteran, Microsoft Most Valuable Researcher 2023 & 2024
r1cksec @r1cksec
1K Followers 225 Following Data breach revealed, Malware lurks, silent, stealthy - OSINT tracks the thread. URLs I post may contain malware – be careful and check yourself before running
lazzslayer @lazzslayer
4K Followers 608 Following Red Team | Co-Author of Redefining Hacking | VP for @bsidesnash | Advisory Board for @redteamvillage_ | OSCP, GCPN, CISM, GPEN | 🤠
Lennart @pssvdrctry
113 Followers 411 Following Systemengineer gone InfoSec w/ @ERNW_ITSec. Everything I say is just my opinion. #Powershell #ActiveDirectory #Azure @[email protected]
Kolja @__k0lja
53 Followers 322 Following
Black Hills Informati... @BHinfoSecurity
49K Followers 2K Following Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
Sravan Akkaram @SravanAkkaram
350 Followers 303 Following Cybersecurity Consultant @Microsoft | Microsoft MVR ’22 & ’23 🏆 | Presenter @BlackHat
Geiseric @Geiseric4
922 Followers 167 Following AD/Azure Enthusiast | eCPPTv2 | CRTP | CRTO | CRTE | CRTM | CARTP | CARTE https://t.co/yYy84cNFPw
Hakku @iHakku
25 Followers 79 Following he/him #infosec "Unwissenheit erzeugt viel öfter feste Überzeugungen, als es Wissen tut."
































