Clear advice with a hacker mindset. Specialised in red teaming, trainings and advanced penetration tests.

Amsterdam, The Netherlands
Joined March 2017
Outflank retweeted
One more for the collection - added a Syscalls process dump BOF to the repo. Effectively a port of @OutflankNL's awesome Dumpert. github.com/ajpc500/BOFs/tree…
1
41
83
Outflank retweeted
Just released a new @OutflankNL Cobalt Strike BOF project which uses direct system calls to enumerate processes for specific loaded modules or process handles. E.g. to find open handles to LSASS or processes with CLR loaded for execute-assembly spawnto. github.com/outflanknl/FindOb…
2
111
229
Outflank retweeted
RedELK v2 BETA 3 release is out! Aka the one where you all have been waiting for because it uses docker for easy installation! Get it while its hot at: github.com/outflanknl/RedELK Many thanks to @fastlorenzo and @xychix for their work
4
40
93
Show this thread
To my peers: keep doing what you're doing. I'm proud of you. I'm proud to work with you. And I know the impact we've had and continue to have. It's not always appreciated, not always well communicated, but we're moving the needle too.
3
16
117
Outflank retweeted
Long time in the making, but its finally here: RedELK Version 2 - beta release 1 Go get it here: codeload.github.com/outflank… Some features: > Support for other C2s > Integrated BloodHound > Integrated Jupyter Notebooks > Integrated MITRE ATT&CK viewer > Lots of new dashboards
5
206
442
Show this thread
Outflank retweeted
RedELK now also has better MITRE ATT&CK integration. When you use Cobalt Strike, the TTPs are recorded. RedELK picks these up and gathers this (nothing new). But now these are also put on a dashboard.
2
10
24
Show this thread
Outflank retweeted
If you are not paying attention to the maindev branch of RedELK you are missing out! Here is a sneak peak of just a few of the new things. First things first, the logo still rocks hard in being awful :-) But now it is in SVG so integrates great in the new stack.
3
33
76
Show this thread