Looking for an open-source cyber range solution?
We'are building one ; designed for hands-on security training, community-driven, and freely available. Still a work progress bur Take a look github.com/range42/rang...
Posts by Hyde
Psst... If something malicious runs on your Linux system, would you notice? Most of the time, it just looks like normal activity. That's usually where detection falls apart. I've been updating my Kunai rules to make that easier to spot. The repository now has 200+ rules.
github.com/digisquad-re...
collaborative threat intel platform to identify patterns and artifacts indicating potential exploitation or misuse of Large Language Models - promptintel.novahunting.ai/feed
Pixnapping: Bringing Pixel Stealing out of the Stone Age - www.pixnapping.com/pixnapping.pdf
PhishingSecLists
Github repo with wordlists for #phishing domains investigations:
Wizard.txt - common filenames/directories where they might be saving credentials
Shells.txt - popular shell file names
github.com/spmedia/Phis...
Contributor twitter.com/Edmond_Major
Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware thehackernews.com/2024/12/atta...
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising www.reddit.com/r/ReverseEng...
This is still one of my favorite vids for understanding and finding IDOR vulnerabilities by @stokfredrik.bsky.social. It was the video that inspired me to dive in and get the basics of the idea!
www.youtube.com/watch?v=3K1-...
Pro-tip: gron is awesome for diffing JSON 🥰
github.com/tomnomnom/gron
I've done a whole bunch of talks, interviews and stuff on other people's YouTube channels over the years so I'm going to try and catalog them here.
First up is a video with my good friend STÖK in which I demo some big bounty workflow stuff.
This one is special.
youtu.be/l8iXMgk2nnY
DarkFlare - TCP-over-CDN Tunnel : A stealthy command line tool to create TCP-over-CDN(http) tunnels that keep your connections cozy and comfortable (Now with public test relay servers! ) : github.com/doxx/darkflare
fakebrowser : Fake fingerprints to bypass anti-bot systems (Simulate mouse and keyboard operations to make behavior like a real person ) : github.com/kkoooqq/fake...
Scrapling : Undetectable, Lightning-Fast, and Adaptive Web Scraping for Python : github.com/D4Vinci/Scra... credits @D4Vinci1