Serjvg @serjvg
Estoicismo y humanismo como filosofías de vida. Cybersecurity. Red team manager. Joined February 2019-
Tweets839
-
Followers49
-
Following390
-
Likes2K
Cobalt Strike 4.13 has a new Aggressor hook to support BOF cocktails. Here's a quick walkthrough: rastamouse.me/bof-cocktails-…
🤓 On Friday I will have the honor to present the keynote at @SLEUTHCON! Come say hi if you are around!
Here's a /goal prompt I've been using to review my code with Codex. I've had a lot of success finding weird bugs and misconfigurations that way. Feel free to use it and share yours: --- /goal Act as a hostile reviewer of the current uncommitted changes. Assume there are bugs, loopholes, broken assumptions, and misconfigurations hidden in the diff. Your goal is to find them before they reach production. Review the uncommitted changes end to end. Do not only inspect the modified lines. Pull in related files, configs, schemas, policies, tests, routes, API handlers, auth flows, database rules, environment assumptions, and deployment behaviour where relevant. Look specifically for: - Security loopholes - Authorization bypasses - Incorrect trust assumptions - User-controlled input reaching sensitive logic - Missing validation - Broken tenant/team/user scoping - Data exposure - Unsafe defaults - Config mistakes - Broken error handling - Race conditions - State inconsistencies - Payment/subscription/access-control bypasses - Missing auditability - Bugs caused by incomplete refactoring - Tests that pass but do not prove the intended behaviour For every issue found: 1. Explain the issue clearly. 2. Show where it exists. 3. Explain the realistic failure or abuse case. 4. Fix it. 5. Re-check whether the fix introduced new issues. Repeat this loop until the implementation is clean enough to defend in a production review. Run relevant validation commands such as tests, linting, type checks, build checks, or targeted scripts. If no tests exist, say that clearly and recommend the missing coverage. Final output must include: - What was reviewed - Issues found - Fixes applied - Validation performed - Remaining risks - Confidence level - Any recommended follow-up tests or hardening tasks Do not give vague reassurance. Be specific, critical, and evidence-based.
One of the most frequent questions I'm asked is "how do you stay up to date on malware stuff?" Okay, here is a pro tip: 1. Google OTX AlienVault 2. Make account 3. Look at latest 4. Scroll until you find posts from a guy named Petr something-something (has numbers in his name). 4. Follow his account He monitors all the big malware places and shares the URL, hashes, etc. from malware vendors. I've been following this random ass dude for years and getting updates on everything. I have no idea who he is. I don't know where he's from. All I know is his setup is absolute fire and he keeps you up to date on literally everything malware related 24/7 365. He also has stuff from vendors in China, Russia, Japan, etc. Every morning I log into OTX and check up on my boy Petr to see what fire he's bringing me. I love him.
Earlier this year, I wrote about 6x different emulation techniques used by threat actors that silence EDR agents and detection strategies for each one. The diagram of the most common technique using WFP Filters: 🖊️ ipurple.team/2026/01/12/edr…
Silencing the EDR Silencers Analysis of techniques to disable or silence EDR agents and some countermeasures, a post by Jonathan Johnson (@JonnyJohnson_ ) Source: huntress.com/blog/silencing… #redteam #blueteam #maldev #malwaredevelopment
I worked with @svch0st and @TheDFIRReport to put out a report in less than 24 hours. This is especially timely given the threat actor's use of OpenClaw and Claude in the mass exploitation of CVE-2025-55182 (React2Shell). An exposed open directory gave us the full operational footprint: scanner harness, AI-orchestrated post-exploitation, Telegram C2, and thousands of exfiltrated .env files across 900+ confirmed compromises. #Claude #OpenClaw #DFIR
We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting,
Full research, benchmark methodology, scoring breakdown, and the obfuscation techniques that worked: go.es.io/3QSJGnI
Elastic have pushed some new rules to detect DLL loads and API calls, where the call stack contains a module known to be used for ROP gadgets. This includes dfshim.dll, which I use in RTO II.
@DfirDiva @13CubedDFIR Investigating MacOs end points.
📣 I partnered with @13CubedDFIR for another giveaway! 🎁 🏆 Five winners will receive a 13Cubed course of their choice from the list below + a Forensicator T-Shirt. 13Cubed Courses: - Investigating Windows Endpoints - Investigating Windows Memory - Investigating Linux Devices - Investigating macOS Endpoints Each course comes with a Certificate of Completion as well as Certification attempts! On April 25th, entries across social media platforms will be combined, and the five winners will be selected. To Enter: ✅ Like ✅ Share ✅ Comment which course you want to win the most For more information ⬇️ Link to 13Cubed Training: training.13cubed.com 13Cubed Merch Store: shop.13cubed.com #DFIR #DigitalForensics #IncidentResponse
For most of 2025, I was skeptical that AI was already playing a major operational role in real intrusions. Most public examples seemed limited to phishing and supporting tasks. This report by my friend Eyal Eyal lines up with what I have been hearing elsewhere, too - in recent publications and in private conversations with people seeing this stuff up close. I think that phase is over. AI is moving into the operational core of attacks. With stronger models, open models, and jailbroken variants circulating, the economics have changed. Tailored tooling, exploit adaptation, and large-scale analysis get cheaper and faster. I expect AI to play a major role in future campaigns, and that means more variation, more fresh tooling, and less reliance by attackers on recycled code. All the more reason to focus on controls and detections that do not depend only on known samples. Worth reading.
Technical report released: The AI-Assisted Breach of Mexico’s Government Infrastructure gambit.security/blog-post/a-si…
Qilin ransomware deploys sophisticated multi-stage EDR killer targeting 300+ security products. Advanced loader uses SEH/VEH-based obfuscation and kernel manipulation to completely disable endpoint detection systems. Technical breakdown: • Stage 1: Malicious msimg32.dll side-loaded via DLL hijacking, implements slot-policy table for syscall evasion and Halo's Gate technique • Stage 2-3: Complex VEH-based control flow obfuscation, overwrites ExitProcess IAT entry, maps payload into shell32.dll memory space • Stage 4: EDR killer loads rwdrv.sys (abused ThrottleStop driver) for physical memory R/W, hlpdrv.sys for process termination (T1562.001) • Kernel manipulation: Unregisters EDR callbacks for process/thread/image events, overwrites CiValidateImageHeader with ArbPreprocessEntry • Geo-fencing excludes post-Soviet countries, requires admin privileges for driver loading Attack chain systematically blinds behavioral detection before ransomware deployment. Hunt for msimg32.dll side-loading, unsigned drivers in system directories, and unexpected ExitProcess IAT modifications. #DFIR_Radar
Sysmon View 2 is here & is now fully open source! I've rewritten it entirely: New modern UI & many quality-of-life improvements. Thank you all, this rewrite took a long time but was worth it. github.com/nshalabi/Sysmo… #SysmonTools #Sysmon #DFIR #ThreatHunting #BlueTeam #InfoSec
🚨 Big news: New TH Book 🏹 After years in Threat Hunting, I wrote the book I always wanted when I started. The Art of Threat Hunting, practical, technical, no fluff. ⚡Hypothesis generation, queries & adaptation stuff, CTI-driven programs, documentation, team alignment. The full lifecycle. 🦖Full breakdown on the blog: rexorvc0.com 🔗Available on Amazon: amazon.com/Art-Threat-Hun… #threatHunting #BlueTeam #Cybersecurity #Research #CTI #Malware #threat
📌 Looking Back: Iranian APT Infrastructure in Focus hunt.io/blog/iranian-a… Two weeks ago, we analyzed infrastructure linked to several Iranian-aligned threat groups. Pivoting across IPs, hashes, ASNs, and TLS certificates revealed clusters tied to actors like MuddyWater and APT35. In one case, a single IP exposed attacker tooling, additional servers in the same hosting network, and a short-lived Sliver C2 instance. Infrastructure patterns like these often appear weeks before campaigns become widely reported. #ThreatIntelligence #ThreatHunting #CyberSecurity
Collecting ADCS data with NetExec🔥 Thanks to the addition of CertiHound, developed and implemented by 0x0Trace, we can now collect ADCS data using the --bloodhound collector of NetExec. As before, the data is exported as JSON files that can be imported directly into BloodHound.
👁️ LOLC2 Collection of C2 frameworks abusing legitimate services to evade detection Major update: new projects tested, enriched data, and deeper insights. site: lolc2.github.io github: github.com/lolc2/lolc2.gi…
APT confirmation used to take hours. Now it takes 4 minutes. Attack Discovery correlates alerts into a single narrative. A workflow triggers the agent. The agent: • Looks up the hash on VirusTotal • Runs ES|QL queries across your logs • Finds the on-call analyst • Creates a case • Opens a Slack incident channel All before you read the threat intel report.
Maybe you’ve been living in a cave for the last two weeks, but an amazing book on how to combine threat intelligence and artificial intelligence has just come out - "Threat Intelligence. Chaos, Signals, and Attribution. AI Applied to Threat Intelligence" amazon.com/-/es/Alfonso-M… Yes, we are the authors (Alfonso Muñoz, Jacobo Blancas)… and yes, this may not be the best promotion ever. But the quality of the book is good enough to make it worth a try. At the very least, it’s as good as our promotional video :)
🚨 Top 5 Live Intelligence Dashboards You Should Be Watching If you're tracking cyber threats, geopolitical tensions, or OSINT signals in real time, these platforms provide a powerful “single pane of glass” into what’s happening globally: 🌍 LiveUAmap – Real-time conflict and geopolitical event tracking 🔗 liveuamap.com 📊 GDELT Project – Global event monitoring powered by AI across dozens of languages 🔗 gdeltproject.org 🌐 WorldMonitor – Live global incidents, disasters, and security alerts 🔗 worldmonitor.app 🛡️ SOCRadar Cyber Conflict Dashboard – Focused cyber threat intelligence (Iran–Israel context) 🔗 socradar.io/iran-israel-cy… 🧠 Pizzint – OSINT-driven monitoring of leaks, dark web activity, and threat signals 🔗 pizzint.watch These dashboards highlight how OSINT + real-time data + visualization are reshaping situational awareness for both cyber and physical threats. 👉 If you know other high-quality live intelligence dashboards, drop them in the comments — always looking to expand the list. #OSINT #CyberThreatIntelligence #ThreatIntel #Geopolitics #DarkWeb #CyberSecurity #DDW #InfoSec #OpenSourceIntelligence
thiswashacked @bwmbwmbwmbwm
36 Followers 2K Following
Fusion Intelligence C... @stealthmole_int
125K Followers 12K Following StealthMole : #Criminal #Intelligence #Profiling #Investigation Platform, #OSINT #DarkWeb #DeepWeb #Leaked #DataBreach #Terror #Drugs #Cryptoassets #Ransomware
Emarcrypt @emarcrypt
15 Followers 527 Following
KryptoXknight @VsGeno19521
53 Followers 250 Following Simply Complex Constitutionalist, Writer, Entrepreneur, Father, and Patriot.
Jennifer gabriela @Jennife38235659
41 Followers 1K Following
Pablo Malo @pitiklinov
85K Followers 16K Following Psiquiatra, miembro de la Txori-Herri Medical Association y de los Beautiful Brains. Básicamente comparto artículos y cosas que leo que me parecen interesantes.
Sobuj ali Xhxhh @SobujX25130
60 Followers 292 Following
Bot Inmuebles 🤖�... @BotInmuebles
1K Followers 723 Following Apasionado de la #inversioninmobiliaria y la #automatización. Quiero que puedas invertir más con menos esfuerzo y mejores resultados. 👇🏻Newsletter aquí 👇🏻
Intelequia EN @IntelequiaEN
3K Followers 3K Following Let's Innovate ⚡ Specialized in #Azure #Cybersecurity #DNN #AI #LowCode and #NET
vishastra @vishastra12
489 Followers 2K Following 🌐 Cybersecurity Enthusiast | 📚 Aspiring Cybersecurity Analyst | 🛡️ Ethical Hacker | 💻 Penetration Tester | 🎮 CTF Player | 🚀
sad @sec0x25
66 Followers 3K Following
ilaalioui24 @ilaalioui2000
333 Followers 6K Following Cyber Security Researcher|Pentester |Bug Bounty Hunter》》》》Read Teamer
A B A @ShantoShan81871
6 Followers 644 Following
rakesh shara @RakeshShara
1 Followers 6 Following
Doclemin @DocHdhana
34 Followers 982 Following
Narimanht @Ningyo_tsukai01
16 Followers 921 Following که فرمودی بنده همون عدد چند باشم؟ ((((: https://t.co/NVHIxjIiY1
Sandra @sandra_rochon_
200 Followers 3K Following
Teresa Salazar Garcí... @tsalazargr
6K Followers 191 Following Tech, Roleplaying & General Geekery | Pictured with Alan Turing | She/Her | I tweet in English & Spanish | DMs open 📬
Trust Swiftly @trustswiftly
774 Followers 3K Following Hardware-Anchored IAL3 Verification for FedRAMP High & Distributed Enterprises.
IT-Events @IT_Events_DW
14K Followers 13K Following Organizamos eventos alrededor de la tecnología. Visita https://t.co/LltiHZENE2
Self @futureoftrust
1K Followers 2K Following
ifeoluwaleyi🐐 @AlabiOluwafika3
23 Followers 530 Following God lover, Education, Guidance counsellor, Psychologist, Music, Dance.
Encriptia @encriptia
93 Followers 102 Following Inteligencia Corporativa y Seguridad. Security Operations Center, Ciberseguridad, Formación. Seguridad Esférica.
Cyber Detective💙�... @cyb_detective
62K Followers 3K Following Every day I write about #osint (Open Source Intelligence) tools and techniques. Also little bit about forensics and cybersecurity in general. Work in @netlas_io
Asuna Evans Ruben @asunaevans5
295 Followers 1K Following
Sandra Walker @SandraW20451870
371 Followers 3K Following
allsafe @0xallsafe
290 Followers 2K Following CTF player , Love tryhackme, HTB , Red teamer , InfoSec Contact [email protected]
Bornunique911 @bornunique911
593 Followers 4K Following Self-taught Cybersecurity enthusiast | 500+ rooms on TryHackMe & HTB | 100+ CTF's via https://t.co/I0tVpqLFOP | CompTIA Sec+ Certified | Always learning & growing
Deborah Galea @deborah_galea
3K Followers 2K Following #cybersecurity evangelist & subject matter expert at @Orcasec | #infosec, #cloudsecurity | #devops, #devsecops, #CISOs.
Kaavs @Kaavs
2K Followers 2K Following An IT Cybersecurity Project Manager, author, artist, creator of Ideas, h4ck3r.
Phillip Watt @Phillbertus
661 Followers 3K Following Infosec, IT, Graphic Design, Multimedia, Cyber Security
Brandon Hoyt 👨🏻... @BrandonRHoyt
18 Followers 500 Following New Twitter profile, under construction! https://t.co/seGq70f4ao
s0crat1c @s0crat1c_1
1K Followers 2K Following With people and situations know the past is the past. If it’s fucked up now and can’t be fixed just find peace in that because it means there’s nothing to do.
Stratodesk @stratodesk
18K Followers 9K Following VDI Endpoint & Management Leader | Thin Client Innovator | x86, ARM/Raspberry Pi | IoT | Citrix Workspace Hub | Cloud #stratodesk
Ahmed @Mawg0ud
4K Followers 3K Following
Joseba Alustiza @jardsjards
25 Followers 110 Following Euskopolis-eko hiritarra, Europazalea. Lehenbizi pertsonak.
Antonymartinini @antonymartinini
0 Followers 65 Following Critical thinking is the beginning of wisdom. 🤯
Marina Moro López @marinamorolopez
359 Followers 401 Following Ingeniera biomédica | Futura doctora en biofísica y bioingeniería | Secretaria de @python_es | Me gusta dar charlas juntando biología y programación 👩🏻🔬🐍
Javier Espadas @JavierMoskva
604 Followers 1K Following Political analysis in CIS/FSU countries. Хотели как лучше, а получилось как всегда. @elOrdenMundial y @elconfidencial
Whitesnake 🛠️ @Whitesnake91
877 Followers 1K Following Yo no soy comunista... Puedo ser un mentiroso, un cerdo, un idiota, un comunista... ¡Pero de actor porno no tengo nada!
Kuzk @Kuzker
113 Followers 254 Following
yeray esteban @YerayEsteban97
36 Followers 185 Following
X-C3LL @TheXC3LL
5K Followers 632 Following Just a biologist that loves to break cyber-stuff. Ka0labs / @AdeptsOf0xcc / ID-10-Ts member. 🦉
Jacob Krell @hackerfren
2K Followers 736 Following Hacker | Pilot | Lifter | OSCE3, CISSP, CCNP | Top 20 Hack the Box | World’s first Certified Offensive AI Expert (COAE) | reviews & writeups | meme magic 🐸
Aaron Jornet @RexorVc0
5K Followers 401 Following Threat Researcher at @socradar | Malware Researcher | Threat Hunter | CTI ¦ Former @ElevenPaths @Panda_Security 📖Book: https://t.co/ZmIUPBuNKG
Elastic Security Labs @elasticseclabs
6K Followers 727 Following Elastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
Yazidou @xacone_
1K Followers 276 Following Another infosec noobie | training @hackthebox_eu | https://t.co/GjpAvsw9YB | 🏴☠️
Smukx.E @5mukx
24K Followers 213 Following Adversary Simulation & Malware Research Lead | Developing powerful softwares for Red Team Engagements | 0x15 Y/o
Gray Swan AI @GraySwanAI
3K Followers 14 Following Empowering the world to use AI safely and securely. Join us: https://t.co/MedOJ4nLiQ
𝕏 Bug Bounty Write... @bountywriteups
40K Followers 4K Following 🔍 Bug Bounty Hunter | Content Creator | Sharing cybersecurity write-ups & resources | AI | | by @piyush_supiy #bugbounty #bugbountytips
Nick VanGilder @nickvangilder
4K Followers 3K Following Director of Offensive Security Operations at Fortune 500 Bank
TheRealCherokeeOwl �... @CherokeeOwl
123K Followers 10K Following You Only Need To Know The Direction, Not The Destination 🇺🇸 🦉History, True Crime, Heroes🚫Lists https://t.co/4QgpFDWoFV
Jaime Gómez-Obregón @JaimeObregon
135K Followers 108 Following Ingeniero hackeando para mejorar la Administración pública. https://t.co/QkIuB8saBA
Lindsay Kaye @TheQueenofELF
1K Followers 264 Following VP of Threat Intelligence @SecurewithHUMAN | Reverse Engineer | Conference Speaker | Ransomware Columnist
World Central Kitchen @WCKitchen
289K Followers 640 Following WCK immediately prepares & serves fresh, nourishing meals to communities impacted by natural disasters and during humanitarian crises. #ChefsForTheWorld
ATC Investing @etc_facts
8K Followers 3K Following Inversor a Largo Plazo desde 2011 📊 Información Financiera Variada🔥Acciones y Fondos de Inversión.
Phantom Security Grou... @phantomcybersec
303 Followers 109 Following Automating the hard parts of Offensive Security. Creators of EvadeX and ApeX
Unit 42 @Unit42_Intel
70K Followers 81 Following The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
Matthew @embee_research
14K Followers 2K Following Security Researcher, Creating and Sharing Educational Content.
3xp0rt @3xp0rtblog
16K Followers 172 Following Malware and cybercrime | Cyber Threat Intelligence Analyst at @PRODAFT https://t.co/FMGOkGnMR8
Cyber_OSINT @Cyber_O51NT
23K Followers 316 Following #OSINT treasure hunter, investigator, #CyberThreatIntel analyst. Opinions are my own. Follow me on Telegram https://t.co/i6VBbeUXgd for cyber news.
Fondos A Fondo @Fondos_A_Fondo
31K Followers 1K Following Asesor Financiero @efpa (35.814) y analista de fondos de inversión Newsletter gratuita (10.000 suscriptores)
Bellingcat @bellingcat
718K Followers 74 Following Support our charity https://t.co/XMTKIEDiTB Buy our book: https://t.co/2JiuWFfTpO Follow us: https://t.co/LPUEQI8TdZ
N @justt_N
4K Followers 99 Following | Martial Artist | Security Researcher | APT: Advanced Persistent Trolling | @X | 🇨🇦
Koodous @koodous_project
2K Followers 5 Following Collaborative platform for Android apps analysis. https://t.co/cCck9pLMYO https://t.co/DnrjjKwxEZ
4n6lady @4n6lady
63K Followers 660 Following #DFIR & #BlueTeam | IR & Threat Detection | #OSINT enthusiast | waiting for HL3 | AWS CIRT - my views are my own
Juan Ramón Rallo @juanrallo
493K Followers 317 Following Doctor en Economía, decano de @Univhesperides y profesor en @en_UFMMadrid.
BRICS News @BRICSinfo
2.1M Followers 2 Following We are an independent media company bringing you unparalleled coverage of all-things geopolitics & BRICS News in real-time. Not an official government account.
The Wall Street Journ... @WSJ
21.9M Followers 1K Following Sign up for our newsletters and alerts: https://t.co/QevH0DLQi8 | Got a tip? https://t.co/iXIigdPjEZ | For WSJ customer support: https://t.co/DZgH9n53qg
The New York Times @nytimes
53.7M Followers 849 Following News tips? Share them here: https://t.co/ghL9OoYKMM
The Telegraph @Telegraph
3.4M Followers 825 Following The Daily Telegraph & Sunday Telegraph We speak your mind. Join the conversation today.
Financial Times @FinancialTimes
7.3M Followers 983 Following This account is now closed. For the best of FT journalism, including breaking news and analysis, follow @ft
0x6rss @0x6rss
18K Followers 937 Following OSINT & malware enthusiast, CTI analyst https://t.co/bktDzzYyfz
Lena Yu @LambdaMamba
5K Followers 543 Following Creator of https://t.co/kdXvRaVEEf | Founder of @MalwareVillage | (Un)Natural Scientist | 🇬🇧 with wife ❤️
Nancy Pelosi Stock Tr... @pelositracker
1.8M Followers 724 Following Highlighting Politicians' trades so we can invest alongside. $1.7B invested alongside via @joinAutopilot Download Autopilot to trade like a politician
TSIP @saferinternetpr
3K Followers 313 Following The internet’s most practical cybersecurity training. Hands on labs, operator level coaching and real client workflows. Where beginners turn into professionals
Grant Collins @collinsinfosec
4K Followers 123 Following 🔍 Infrastructure & Detection Security Engineer 🚀 Build Experience With Your Homelab: @projectsecio 📽️ YouTube: https://t.co/WCRdqzv6fO
Glambase.app @GlambaseApp
12K Followers 179 Following https://t.co/4PbOztEXrm — create and monetize AI influencers
Alberta Tech @albertadevs
20K Followers 707 Following I make funny videos about tech + AI ex-@google engineer (but in a fun and chill way)
Tom Dörr @tom_doerr
215K Followers 3K Following Follow for posts about GitHub repos, DSPy, and agents Subscribe for top posts DM to share your AI project (Due to volume of DMs I'll prioritize subscribers)
HackTricks @hacktricks_live
15K Followers 204 Following HackTricks offers free quality hacking resources in 17 languages: https://t.co/O1TVFk5r9q, https://t.co/0RhWRaaPIm Paid certs by HT-Training: https://t.co/2C0w8pkq6v
🄲🅈🄱🄴🅁 ... @Cyber_Asia_
4K Followers 565 Following Follow us for the latest #cybersecurity news in Asia.
Anuj Soni @asoni
3K Followers 359 Following Malware Reverse Engineer. Instructor & Author. Occasional YouTuber.
Dark Web Informer @DarkWebInformer
224K Followers 84 Following One guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!






























