Paul Seekamp (@nullenc0de) 's Twitter Profile
Paul Seekamp

@nullenc0de

I spend a significant amount of time reading security stuff.

Co-Founder/Partner @CoastlineCyber

leanpub.com/internal-field…

ID: 456074700

linkhttps://coastlinecyber.com calendar_today05-01-2012 21:05:08

5,5K Tweet

17,17K Followers

604 Following

dreadnode (@dreadnode) 's Twitter Profile Photo

Can we eliminate the C2 server entirely and create truly autonomous malware? On the Dreadnode blog, Principal Security Researcher Max Harley details how we developed an entirely local, C2-less malware that can autonomously discover and exploit one type of privilege escalation

Can we eliminate the C2 server entirely and create truly autonomous malware?

On the Dreadnode blog, Principal Security Researcher <a href="/0xdab0/">Max Harley</a> details how we developed an entirely local, C2-less malware that can autonomously discover and exploit one type of privilege escalation
Smukx.E (@5mukx) 's Twitter Profile Photo

Trust Issues – Attacking Trust in Active Directory TLDR; this blog covers attack chains abusing Trust account TDO in One-Way Outbound & Bidirectional Trusts. What the TDO can/can't do and Compromise shura.lab via shared CA trust in kapla.lab lorenzomeacci.com/trust-issues-a…

Trust Issues – Attacking Trust in Active Directory

TLDR; this blog covers attack chains abusing Trust account TDO in One-Way Outbound &amp; Bidirectional Trusts. What the TDO can/can't do and Compromise shura.lab via shared CA trust in kapla.lab

lorenzomeacci.com/trust-issues-a…
SpecterOps (@specterops) 's Twitter Profile Photo

Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️ ghst.ly/4qtl2rm

Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷 (@k8em0) 's Twitter Profile Photo

Even with patches provided with bug reports, AI makes too much human work in prioritizing & testing. Commercial closed source faces similar bottlenecks & diminishing security returns. Vuln handling can’t keep up even if using AI validation. Security is being DoSed by AI right now

Paul Seekamp (@nullenc0de) 's Twitter Profile Photo

I think that AI is cool, but it's supplemental still. Not a replacement yet. Watching these AI pentests run by non SME is a time and money suck. Only use AI on stuff you can validate people.

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

We know that Microsoft improved the overall printing security in 2025, now using DCE/RPC for callback, you can force NTLM local auth and reflect back machine auth even without CredMarshalTargetInfo() trick 😇

We know that Microsoft improved the overall printing security in 2025, now using DCE/RPC for callback,  you can force NTLM local auth and reflect back machine auth even without CredMarshalTargetInfo() trick 😇