Stan Hegt (@stanhacked) 's Twitter Profile
Stan Hegt

@stanhacked

Red teamer @ Outflank

ID: 3404758191

linkhttps://www.outflank.nl calendar_today05-08-2015 21:52:03

296 Tweet

5,5K Followers

157 Following

Outflank (@outflanknl) 's Twitter Profile Photo

Let's explore the intricate dance of virtual to physical memory mapping in BYOVD tooling development! πŸ’» In Cedric Van Bockhaven's latest blog we delve into resolving addresses using Superfetch, unlocking control over physical memory. Dive into the details now πŸ‘‰ outflank.nl/blog/2023/12/1…

Outflank (@outflanknl) 's Twitter Profile Photo

With his ability to stealthily get into houses, Santa is a natural red teamer, which is why he’s giving you the gift of offensive security! Register now for a free training course on Microsoft Office tradecraft, taught by Stan Hegt and Pieter Ceelen outflank.nl/free-training-…

With his ability to stealthily get into houses, Santa is a natural red teamer, which is why he’s giving you the gift of offensive security! 

Register now for a free training course on Microsoft Office tradecraft, taught by <a href="/StanHacked/">Stan Hegt</a>  and <a href="/ptrpieter/">Pieter Ceelen</a> 

outflank.nl/free-training-…
Philippe Lagadec (@decalage2) 's Twitter Profile Photo

This training was really awesome, I learnt quite a few new tricks that still work on MS Office! thank you Stan Hegt and Pieter Ceelen I might have a few ideas to improve oletools 😎

Outflank (@outflanknl) 's Twitter Profile Photo

The PowerShell mafia is back! We are giving a Tech Deep Dive session right now where we look at new OST tools to leverage PowerShell for local and remote code execution. PowerShell is not dead for red teams! Available for #OST customers. More info at outflank.nl/ost

The PowerShell mafia is back! 

We are giving a Tech Deep Dive session right now where we look at new OST tools to leverage PowerShell for local and remote code execution. PowerShell is not dead for red teams! 

Available for #OST customers. More info at outflank.nl/ost
Stan Hegt (@stanhacked) 's Twitter Profile Photo

I will be at GISEC GLOBAL in Dubai on April 23rd+24th to represent Outflank and our parent company Fortra. If you want a private demo of our toolkit for red teams Outflank Security Tooling (OST) and Cobalt Strike then drop me a line or visit our booth at Hall 6/C75.

I will be at <a href="/GISECGlobal/">GISEC GLOBAL</a> in Dubai on April 23rd+24th to represent <a href="/OutflankNL/">Outflank</a> and our parent company <a href="/fortraofficial/">Fortra</a>.

If you want a private demo of our toolkit for red teams Outflank Security Tooling (OST) and Cobalt Strike then drop me a line or visit our booth at Hall 6/C75.
Outflank (@outflanknl) 's Twitter Profile Photo

Initial access to the max! We just released a new OST tool, using our research and full weaponisation of an obscure file format. This file format allows shellcode loading with just a double click and is under less MotW scrutiny than most other popular initial access vectors. πŸ’ͺ

Initial access to the max!

We just released a new OST tool, using our research and full weaponisation of an obscure file format.

This file format allows shellcode loading with just a double click and is under less MotW scrutiny than most other popular initial access vectors. πŸ’ͺ
Outflank (@outflanknl) 's Twitter Profile Photo

Want to see this new initial access tool in action? Register for next week's demo on May 30. We'll show this tool, together with other tools and features of Outflank Security Tooling. register.gotowebinar.com/register/29489…

Stan Hegt (@stanhacked) 's Twitter Profile Photo

🏁 InfoSec Kart Cup 2024 is heating up! 🏎️ We already have 30 teams ready to race! Blue team defenders and red team attackers, come challenge your peers in this outdoor karting showdown. πŸ“ Berghem, NL πŸ“… June 27 Check our "special" website for details: infoseckartcup.nl

🏁 InfoSec Kart Cup 2024 is heating up! 🏎️

We already have 30 teams ready to race! Blue team defenders and red team attackers, come challenge your peers in this outdoor karting showdown.

πŸ“ Berghem, NL
πŸ“… June 27

Check our "special" website for details: infoseckartcup.nl
Outflank (@outflanknl) 's Twitter Profile Photo

It's not *always* about Windows--macOS and Linux #EDRs need attention, too! In our latest blog, Kyle Avery explains more about the telemetry sources for these under-discussed #endpoint products> outflank.nl/blog/2024/06/0…

It's not *always* about Windows--macOS and Linux #EDRs need attention, too! In our latest blog, <a href="/kyleavery_/">Kyle Avery</a>  explains more about the telemetry sources for these under-discussed #endpoint products&gt;

outflank.nl/blog/2024/06/0…
Outflank (@outflanknl) 's Twitter Profile Photo

πŸ”₯πŸ”₯New goody dropped for Outflank Security Tooling customers: PhisherPrice PhisherPrice helps with Device Code Flow abuse without sending codes/QRs via email. Easy to setup and host a phishing website, easy to receive auth tokens. Just as you like it.

Outflank (@outflanknl) 's Twitter Profile Photo

New Blog Alert! 🚨 Introducing Early Cascade Injection, a stealthy process injection technique that targets Windows process creation, avoids cross-process APCs, and evades top-tier EDRs. Learn how it combines Early Bird APC Injection & EDR-Preloading: outflank.nl/blog/2024/10/1…

New Blog Alert! 🚨

Introducing Early Cascade Injection, a stealthy process injection technique that targets Windows process creation, avoids cross-process APCs, and evades top-tier EDRs. 

Learn how it combines Early Bird APC Injection &amp; EDR-Preloading: outflank.nl/blog/2024/10/1…
Outflank (@outflanknl) 's Twitter Profile Photo

πŸš€ We're hiring a DevOps/Cloud Engineer at Outflank! Join us to build and manage complex Azure environments that deliver our OST toolkit. Skills: Kubernetes (AKS), GitOps, IaC, Tekton, PythonπŸ’» It's NOT an offensive role! Based in NL or a time zone-friendly region? Let's chat!

Outflank (@outflanknl) 's Twitter Profile Photo

Yes! We're doing the Infosec Kart Cup again! 🏎️🀘 Mark June 19 in your calendars, and reserve your spot now at infoseckartcup.nl! The 2024 edition was sold out.

Yes! We're doing the Infosec Kart Cup again! 🏎️🀘

Mark June 19 in your calendars, and reserve your spot now at infoseckartcup.nl!  The 2024 edition was sold out.
Outflank (@outflanknl) 's Twitter Profile Photo

Here's our new blog on hiding your implant in VTL1, where even an EDR's kernel sensor can't see it.πŸ§‘β€πŸ¦― Post includes full operational details. Plus our OST offering has been updated with a Cobalt Strike sleep mask exploiting secure enclaves. Full read ➑️ outflank.nl/blog/2025/06/1…

Outflank (@outflanknl) 's Twitter Profile Photo

BOFs are powerful, but error-prone! We dropped a post and new BOF linting tool to catch bugs early, and to prevent crashing implants. This will speed up your Beacon Object File dev workflow. If you're building custom C2 payloads, it's a must-read. πŸ” πŸ“– outflank.nl/blog/2025/06/3…

Outflank (@outflanknl) 's Twitter Profile Photo

Have you always wanted to roll out your own offensive monitoring network? See how Async BOFs enable automatic notifications for when users log in, useful applications (such as password vaults) are started, or the user tries to log off/shut down. outflank.nl/blog/2025/07/1…

Have you always wanted to roll out your own offensive monitoring network? See how Async BOFs enable automatic notifications for when users log in, useful applications (such as password vaults) are started, or the user tries to log off/shut down.  outflank.nl/blog/2025/07/1…
Stan Hegt (@stanhacked) 's Twitter Profile Photo

The Outflank and Cobalt Strike researchers will be hosting 15 minute technical lightning talks at our BlackHat USA booth. ⚑️ There's some really good content in there that you don't want to miss. πŸ“Booth #4422 (Fortra) πŸ•’ See attached schedule. Limited spots, so come early!

The Outflank and Cobalt Strike researchers will be hosting 15 minute technical lightning talks at our BlackHat USA booth. ⚑️ There's some really good content in there that you don't want to miss.

πŸ“Booth #4422 (Fortra)
πŸ•’ See attached schedule. Limited spots, so come early!
Outflank (@outflanknl) 's Twitter Profile Photo

Black Hat Bonus: Learn more about Kyle Avery 's research on training self-hosted LLMs to generate evasive malware and creation of a 7B parameter model that generates evasive Cobalt Strike shellcode loaders able to bypass Microsoft Defender for Endpoint. ow.ly/1EUf50WBI5e

Black Hat Bonus: Learn more about <a href="/kyleavery_/">Kyle Avery</a> 's research on training self-hosted LLMs to generate evasive malware and creation of a 7B parameter model that generates evasive Cobalt Strike shellcode loaders able to bypass Microsoft Defender for Endpoint. ow.ly/1EUf50WBI5e