r1cksec

Data breach revealed,
Malware lurks, silent, stealthy -
OSINT tracks the thread.

URLs I post may contain malware – be careful and check yourself before running anything.

2026-02-26

A new ClickFix variant dubbed "CrashFix" that intentionally crashes the browser then baits users into running malicious commands

huntress.com/blog/malicious-br

#infosec #cybersecurity #threatintel #phishing #malware #redteam

2026-02-24

GitPhish is a comprehensive security research tool designed to perform GitHub's device code authentication flow.

github.com/praetorian-inc/GitP

#infosec #cybersecurity #redteam #pentest #phishing

2026-02-22

This post describes how to execute code on every Pod in many Kubernetes clusters when using a service account with nodes/proxy GET permissions

grahamhelton.com/blog/nodes-pr

#infosec #cybersecurity #redteam #pentest

2026-02-21

A lightweight command sandbox for Linux, secure-by-default, built on Landlock

github.com/dwisiswant0/sandbox

#infosec #cybersecurity #pentest #threatintel

2026-02-18

The Mimikatz Missing Manual (a deep-dive guide to Windows Identity, Kerberos, and PKI Research)

github.com/darkoperator/mimika

#infosec #cybersecurity #redteam #pentest

2026-02-16

An entertaining post on how TaskHound was refactored to fix real‑world issues

r0bit.io/posts/taskhound/part2

#infosec #cybersecurity #redteam #pentest

2026-02-15

Project for generating and identifying deceptive LNK files

github.com/wietze/lnk-it-up

#infosec #cybersecurity #redteam #phishing #opensource

2026-02-14

A Bloodhound alternative. BloodBash will ingest the same files bloodhound does but no server is required to use this tool. It's great for quick AD enumeration

github.com/DotNetRussell/Blood

#infosec #cybersecurity #redteam #pentest #opensource

2026-02-11

Ax Framework is a free and open-source tool utilized by Bug Hunters and Penetration Testers to efficiently operate in multiple cloud environments. It helps build and deploy repeatable infrastructure tailored for offensive security purposes

github.com/attacksurge/ax

#infosec #cybersecurity #redteam #pentest #opensource

2026-02-10

The project also contains a tool to manipulate the msDS-KeyCredentialLink LDAP attribute in order to register KeyCredentialLinks in Active Directory environments

github.com/RedTeamPentesting/k

#infosec #cybersecurity #redteam #pentest #opensource

2026-02-07

A powershell tool to enumerate all SharePoint sites/drives that a user can access via Microsoft Graph, recursively downloads files, and logs every Graph/SharePoint HTTP request for SIEM correlation

github.com/zh54321/SharePointD

#infosec #cybersecurity #redteam #pentest #cloud

2026-01-31

A collection of intel and usernames scraped from various cybercrime sources & forums. DarkForums, HackForums, Patched, Cracked, BreachForums, LeakBase, & more

github.com/spmedia/Threat-Acto

#infosec #cybersecurity #threatintel

2026-01-30

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint List and exfiltrate files using Google Drive or Microsoft SharePoint Document.

github.com/looCiprian/GC2-sheet

#infosec #cybersecurity #redteam #pentest #threatintel #dfir

2026-01-29

This project maintains a list of binaries natively available in Proxmox VE that can be leveraged by adversaries during red team operations

lolprox.yxz.red

#infosec #cybersecurity #redteam #pentest

2026-01-26

Custom Google search engine dedicated to IT security & hacking stuff. Over 240 high-quality sources.

github.com/Print3M/Google-Hack

#infosec #cybersecurity #redteam #pentest #threatintel #malware #bugbounty

2026-01-24

Proof of Concept for extracting NTLMv1 hashes from sessions on Windows (relies on the Remote Credential Guard protocol).

github.com/bytewreck/DumpGuard

#infosec #cybersecurity #redteam #pentest #windows

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst