@dtmsecurityi
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
security engineer / hacker / red teamer / researcher
United Kingdom
Joined August 2011
- Tweets2.5K
- Following1.1K
- Followers2.8K
- Likes7.3K
Since everyone’s seeing what fruit flys can do - here’s a fly powered fish inspired by MOPy fish from the 90s - fish.rap.sh/?brain=1&unlock=…
DTM retweeted
📁 .ppkg files are Microsoft deployment containers used to configure Windows devices. @dtmsecurity wrote about these and how to abuse them for code execution.
🧐 So I went back and reproduced the technique to identify detection indicators.
🖊️ ipurple.team/2026/08/04/prov…
Next week I’m Vegas-bound. On Thursday I’ll be speaking at the AI Security Forum. Looking forward to sharing some AI research, presenting on something other than traditional red teaming for a change, and of course catching up with lots of humans.
Once weights are in the wild, the control surface moves from API governance to local modification. @dtmsecurity maps the "abliteration" scene and what breaks once safeguards can be stripped offline.
For session times & detail, check our conference app.
#AISecurity
DTM retweeted
Once weights are in the wild, the control surface moves from API governance to local modification. @dtmsecurity maps the "abliteration" scene and what breaks once safeguards can be stripped offline.
For session times & detail, check our conference app.
#AISecurity
DTM retweeted
Note on WordPress pre-auth RCE (CVE-2026-63030). There are SQLi poc's out there, but RCE PoC has not yet been exploited in the wild. Will only release our technical post if we have proof of exploitation. Our RCE payload does NOT require poorly configured MySQL.
DTM retweeted
Why yes, yes we can use ESTSAUTH captured from evilginx to automatically register a passkey
Replying to @NathanMcNulty
This is super cool! (just catching up late after the weekend)
Is it possible to generate that passkey using the previously captured cookies or tokens, through phishing? (using browser cookies in general)
DTM retweeted
you can use gmod to verify your age by the way
Discord announces that users will need to verify their age from early March onwards in-order-to access age restricted content.
All accounts will be set to a “teen-by-default” experience until otherwise verified as an adult.
(discord.com/press-releases/d…)
DTM retweeted
Wow this post really blew up! If you want to know more about the smallest possible files that do things, check out the 6th annual Binary Golf Grand Prix, happening now til January 18th!
nitter.cf/binarygolf/status/1979…
Binary Golf Grand Prix 6 begins now!
#BGGP6 theme: "Recycle"
DTM retweeted
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
sensepost.com/blog/2025/pwni…
sensepost.com/blog/2025/pipe…
DTM retweeted
Would you like to be my colleague, and get to wear an awesome red hoodie? We are looking for a full-stack / offensive developer. Drop me a message or apply directly: job-boards.greenhouse.io/for…
DTM retweeted
We are giving away 1 free spot for level ZERO.
If you are a cyber pro or tech bro and want a full system reset - now is your chance.
To enter: 🔄 retweet
Bonus entry: 💬 comment below - 1 thing you want to fix in the new year.
Winner announced Friday.
#wehackhealth
DTM retweeted
Part 1 of my #BGGP6 writeup about nasm's most mysterious object file format, RDOFF.
n0.lol/bggp6-rdoff/
Today I got RDOFF (.rdf) files working in nasm 2.15. I wrote my own lib bc nasm didn't generate properly. Also patched the 32-bit loader in `rdx` with mmap tricks (shoutout ixi). An executable RDOFF has likely never run on a 64 bit system before today. Writeup soon! #BGGP6
DTM retweeted
Slides and Such for my @BSidesVienna talk about Linux H4x as just a bunch of syscalls, Living Under the Land on Linux
Slides: docs.google.com/presentation…
and Such: github.com/magisterquis/lutl…
Released a write up for three python pip package entries for #BGGP6 - rap.sh/Python_Pip_Golf
Binary Golf Grand Prix 6 begins now!
#BGGP6 theme: "Recycle"
DTM retweeted
New writeup for #BGGP6 !!
What's the smallest Wireshark dissector? What's the most annoying Wireshark dissector?
Find out here: n0.lol/bggp6-wireshark/
DTM retweeted
Last month, @d_tranman and I gave a talk @MCTTP_Con called "COM to the Darkside" focusing on COM/DCOM cross-session and fileless lateral movement tradecraft.
Check out the slides here: github.com/bohops/COM-to-the…
Recording should be released soon.
DTM retweeted
Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ⤵️ ghst.ly/4qtl2rm
DTM retweeted
Challenge Announcement: binary.golf/6