@max__grim

Red Teamer @OutflankNL | Cyber Security | Messing around with hardware

NL
Joined June 2010
Max Grim retweeted
Infosec tradecraft just became reusable by AI agents. SpecterOps just open-sourced: 79 skills. 22 reusable agents. 26 plugin families. BloodHound. Cobalt Strike. Outflank C2. Ghidra. Binary Ninja. Ghostwriter. Recon. AppSec. Code review. C2 development. Reverse engineering. Adversary simulation. Windows + macOS tradecraft. And this is NOT just for red teamers. Vulnerability researchers: These workflows could accelerate code review, patch analysis, 1-day research and potentially help with 0-day discovery when paired with real research expertise. Reverse engineers + malware analysts: Give agents structured workflows, references and tooling instead of starting every investigation from a blank prompt. Blue teams + detection engineers: Study the same offensive tradecraft, emulate attacker behavior, build better detections and start asking what telemetry survives increasingly agent-assisted operations. DFIR + threat intel: Understand what adversaries may automate next and turn repeatable investigative knowledge into reusable workflows. Red teamers: BloodHound attack paths, recon, C2 development, adversary simulation and operator tradecraft are becoming increasingly agent-assisted. This isn't another collection of AI prompts. It's practitioner knowledge being turned into reusable, reviewable security workflows. Potentially useful for everyone from CTF learners and newcomers all the way to malware analysts, reverse engineers, exploit devs, red teams, blue teams and vulnerability researchers. This is only the beginning. @SpecterOps Skills: github.com/SpecterOps/skills @OutflankNL and @kyleavery breakdown: outflank.nl/blog/2026/09/02/… #Infosec #RedTeam #ReverseEngineering
11
210
2
977
56,565
Max Grim retweeted
RedTreat day 2 😎
5
3
55
4,369
Max Grim retweeted
Outflank is proud to have collaborated with @SpecterOps on a new red team AI skills marketplace. This collection packages offensive security knowledge into reusable skills for AI agents. Read more on our blog: outflank.nl/blog/2026/09/02/…
1
32
1
137
7,004
Next august, we'll host our newly designed advanced defensive engineering training at @BlackHatEvents in Las Vegas. Next to detection engineering we'll also cover topics like enrichment, lifecycle management and AI. There are still some spot left! blackhat.com/us-26/training/…
10
19
4,165
Max Grim retweeted
Red teaming && racing, two of my main interests, now together in 1 event! Come and join me on May 27 at Racesquare Utrecht to hear me talk about red team tooling, and to jump in a virtual F1 car for a race. More info on this *free* event: the-s-unit.nl/fortra-event/
1
4
267
New blog by Outflank’s @KyleAvery: Linux process injection leveraging seccomp to inject shared libraries into Linux processes without LD_PRELOAD, ptrace nor elevated privileges. Parent-to-child injection at any ptrace_scope level 💪😎 Tech details here: ow.ly/KwBh50XGvrC
1
54
2
151
13,231
Would you like to be my colleague, and get to wear an awesome red hoodie? We are looking for a full-stack / offensive developer. Drop me a message or apply directly: job-boards.greenhouse.io/for…
5
6
27
4,234
4.12 has been a blast to work on, and it’s awesome to see it release! Happy tinkering 😁
Cobalt Strike 4.12 is LIVE, complete with a new look for the GUI! Additionally, we're introducing: - A REST API - User Defined Command and Control (UDC2) - New process injection options - New UAC bypasses - and more! Check out the release blog for details. ow.ly/RSmE50Xx1OS
2
37
4,848
Credential Guard was supposed to end credential dumping. It didn't. @bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️ ghst.ly/4qtl2rm
11
335
20
729
137,760
We're at BlackHat USA. At 1.30 PM our Outflank researcher @kyleavery will present his work on how he trained a 7B parameter LLM to defeat Microsoft Defender for Endpoint. An accompanying blog post will go out later today and we'll release the model on Hugging Face. Stay tuned!
9
44
3,482
The Registry Rundown. Last year Cedric Van Bockhaven & Max Grim showed us how even non-administrators can do some very interesting things with the registry. #Cybersecurity #WindowsRegistry #Infosec Watch here: youtu.be/MxDq552Di3Y?si=eWI8…
3
5
1,328
Yes! We're doing the Infosec Kart Cup again! 🏎️🤘 Mark June 19 in your calendars, and reserve your spot now at infoseckartcup.nl! The 2024 edition was sold out.
3
1
6
2,965
Max Grim retweeted
Automatic browser SSO with a PRT on a victim device over an Outflank C2 implant 🥰 using ROADtools and some hackery from @max__grim
4
27
195
13,687
Headed to Singapore for BlackHat Asia? Be sure to stop by booth 507 to talk all things #offsec and then join @OutflankNL's @max__grim to learn how Outflank C2 (OC2) can cut through the noise and extract critical insights, enabling smarter operations.#BHASIA @BlackHatEvents
2
4
957
Headed to Singapore for BlackHat Asia? Join Outflank's own @max__grim for a deep dive into Outflank C2 (OC2) and discover how it can cut through the noise and extract critical insights, enabling smarter operations.#BHASIA @BlackHatEvents
4
13
1,111
Enjoying @1ns0mn1h4ck? Don't miss @c3c's speaking session on using VBS enclaves for handling sensitive data>
2
17
1,191
Virtual fortresses aren’t as invincible as they seem 🏰⚔️. Read about our latest research on using Secure Enclaves in Windows for offensive ops — plus fresh insights for red teamers. Check out Part 1 of our blog series here: outflank.nl/blog/2025/02/03/…
2
42
1
85
10,837
We worked with @_dirkjan to get this as an exclusive into Outflank Security Tooling with a new tool called ROADtune. ROADtune allows red teamers to: - bypass CAP by faking device compliance registration - loot secrets from applications pushed to compliant devices Cool stuff!
Pretty proud of this one, took a lot of work. And no, this device does not exist 😎
1
33
4
153
25,074
🚀 We're hiring a DevOps/Cloud Engineer at Outflank! Join us to build and manage complex Azure environments that deliver our OST toolkit. Skills: Kubernetes (AKS), GitOps, IaC, Tekton, Python💻 It's NOT an offensive role! Based in NL or a time zone-friendly region? Let's chat!
2
8
1
13
2,719
Max Grim retweeted
Pretty proud of this one, took a lot of work. And no, this device does not exist 😎
15
27
4
220
39,792