@mubix

Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary

The Internet
Joined February 2007
If you have ever learned anything from me at all. I challenge you to pay it forward. I didn’t get to where I am by standing on the shoulders of giants, I got here by learning tidbits from hundreds of tweeters, bloggers, podcasters & presenters who chose to share their knowledge.
43
185
13
1,063
Every time I hear about the advances in Ai and the fears about what it could do and what it is doing to society, I remember this quote from Jurassic Park 1:
3
6
24
2,538
Rob Fuller retweeted
1/4 NetScaler exploitation IOCs (CVE-2026-88771 suspected) 🚨 Sharing detection info from a failed exploitation attempt seen on 22 Sep. Unauthenticated, two-stage, fully automated. Shared for detection only, so you can check your own logs. #NetScaler #Citrix #DFIR
6
32
1
127
12,974
Rob Fuller retweeted
We’re doing this again. hobocon 3 is coming. hobocon 2 put 68 hackers, makers, radio nerds, and assorted weirdos in one train car. For hobocon 3, we’re planning at least twice the nonsense: two train cars and 136 people. Interest form: hobocon.com
1
9
2
21
1,406
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees. So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
2
33
128
18,158
Made a Golang port of it heavily using AI to do so: github.com/mubix/ntlmscout-g… - workflow built out most of the binary versions someone would need. Amazing concept and work by @BoydHacks
Just released ntlmscout, a single-file, zero-dependency recon tool for internet-exposed NTLM endpoints. Combines the best parts of several tools all in one. Decodes the Type-2 challenge across HTTP/SMB/MSSQL/mail/LDAP/RDP, recovers the internal IP (OXID, IIS host-header, cert SANs), flags DCs, and sprays lockout-safe. Hack the Planet! github.com/boydhacks/ntlmsco…
1
4
41
6,014
Added more training to the AI-CTF (it won't be fast but you can run this on a halfway decent laptop) - github.com/mubix/ai-ctf It teaches prompt injection and other paths prompt injection can take. All the answers are in the repo so it isn't about getting the flags but learning.
15
63
1
329
16,994
Rob Fuller retweeted
ItsNotAlwaysSMB: DPAPI in other protocols🔥 SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to @_zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL and various modules🔑
4
110
1
401
15,366
Rob Fuller retweeted
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
76
3
235
18,717
Rob Fuller retweeted
Outflank's ntlmrain takes Google's ~8 TiB NetNTLMv1 rainbow tables and losslessly compresses them to ~3.99 TB using globally sorted endpoints, packed 39 bit chain starts, delta encoding + Rice-16 coding, and a global GIDX index. The result is ~1 min SSD table lookups, WebGPU-accelerated DES precomputation/verification, and ~7 min end-to-end cracking on an RTX 4070 Ti. More Explanation in their blog: outflank.nl/blog/2026/09/08/… Github tool: github.com/outflanknl/ntlmra… NTLMRain Table: lookup.ntlmrain.com #NetNTLMv1
1
16
133
6,344
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). github.com/mubix/cyber-resum…
12
105
2
526
28,344
Not an opportunity you want to miss if you are hiring.
Open for work! My stint at Roblox has ended. Looking for interesting roles... if you know someone that is looking for someone with my skills, feel free to point them in my direction :)
2
12
5,041
Rob Fuller retweeted
Open for work! My stint at Roblox has ended. Looking for interesting roles... if you know someone that is looking for someone with my skills, feel free to point them in my direction :)
10
36
3
160
33,201
Heard this fantastic quote today: “Mentorship is about making equals (or betters), not followers. If your mentee wants to be a follower it will never work. If your mentor just wants followers it will never work. Find someone that wants to be or to build an equal”
4
10
2
54
6,001
I built BloodBash to help me pass my OSCP+ with more confidence It worked The most surreal thing I experienced at DefCon 34 though was random people telling me they used it to pass their OSCP also. If you have feedback please share it. I want to make it the best tool we can @offsectraining @defcon #hacktheplanet #activedirectory #oscp #redteam #pentetrationtesting github.com/SquidSec/BloodBas…
7
90
2
510
22,955
Rob Fuller retweeted
#x33fcon 2026 talks: @k3vinTell & @RWXstoned - DDD: DCOM, DotNet, Deserialization > youtu.be/lQD_Pz4IR5A
1
20
1
58
5,468
Rob Fuller retweeted
Introducing GLM-5.3: Built to Code. Ready for Cyber Defense. - Top-tier coding and agentic capabilities, achieved through post-training on the 743B base model - A major leap in cybersecurity, setting a new standard among open models Tech Blog: z.ai/blog/glm-5.3
949
2,363
1,668
19,279
5,912,201
Rob Fuller retweeted
🚨 This one's nasty. Googled "codex macbook download" — first result is a sponsored ad pointing to chatgpt.com. The real domain. It opens a shared ChatGPT chat with friendly install steps: open Terminal, paste this command. That command hides a base64 string. Decoded 👇 curl to trekmesh15[.]com — a known ClickFix domain dropping MacSync Stealer. Passwords, keychain, crypto wallets. Gone. So the infection chain is: Google Ad → legit chatgpt.com share link → you infect yourself. No exploit. No download. Just trust in a Google ad and a ChatGPT page. Don't ever paste Terminal commands from an ad or a shared chat. Tell your Mac friends.
52
196
51
1,224
163,109
Rob Fuller retweeted
Bypassing server-side validation on a SaaS target .Spoofed GIF magic bytes inside the JSON payload & tricked the API into signing an AWS S3 PUT URL for an SVG.
1
6
61
6,306