@mubixi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
The Internet
Joined February 2007
- Tweets33.5K
- Following24.8K
- Followers77.9K
- Likes5.3K
Pinned Tweet
If you have ever learned anything from me at all. I challenge you to pay it forward. I didn’t get to where I am by standing on the shoulders of giants, I got here by learning tidbits from hundreds of tweeters, bloggers, podcasters & presenters who chose to share their knowledge.
Every time I hear about the advances in Ai and the fears about what it could do and what it is doing to society, I remember this quote from Jurassic Park 1:
Rob Fuller retweeted
1/4 NetScaler exploitation IOCs (CVE-2026-88771 suspected) 🚨
Sharing detection info from a failed exploitation attempt seen on 22 Sep. Unauthenticated, two-stage, fully automated. Shared for detection only, so you can check your own logs.
#NetScaler #Citrix #DFIR
Rob Fuller retweeted
We’re doing this again. hobocon 3 is coming.
hobocon 2 put 68 hackers, makers, radio nerds, and assorted weirdos in one train car.
For hobocon 3, we’re planning at least twice the nonsense: two train cars and 136 people.
Interest form: hobocon.com
Rob Fuller retweeted
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees.
So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
Made a Golang port of it heavily using AI to do so: github.com/mubix/ntlmscout-g… - workflow built out most of the binary versions someone would need.
Amazing concept and work by @BoydHacks
Just released ntlmscout, a single-file, zero-dependency recon tool for internet-exposed NTLM endpoints. Combines the best parts of several tools all in one.
Decodes the Type-2 challenge across HTTP/SMB/MSSQL/mail/LDAP/RDP, recovers the internal IP (OXID, IIS host-header, cert SANs), flags DCs, and sprays lockout-safe.
Hack the Planet!
github.com/boydhacks/ntlmsco…
Rob Fuller retweeted
Replying to @mubix
great stuff mate, I did something similar: github.com/stratomarco/ai-tr…
Added more training to the AI-CTF (it won't be fast but you can run this on a halfway decent laptop) - github.com/mubix/ai-ctf
It teaches prompt injection and other paths prompt injection can take. All the answers are in the repo so it isn't about getting the flags but learning.
Finally had some time to update IOXIDResolver thanks to a few people submitting changes/issues: github.com/mubix/IOXIDResolv…
Rob Fuller retweeted
ItsNotAlwaysSMB: DPAPI in other protocols🔥
SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to @_zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL and various modules🔑
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
Outflank's ntlmrain takes Google's ~8 TiB NetNTLMv1 rainbow tables and losslessly compresses them to ~3.99 TB using globally sorted endpoints, packed 39 bit chain starts, delta encoding + Rice-16 coding, and a global GIDX index.
The result is ~1 min SSD table lookups, WebGPU-accelerated DES precomputation/verification, and ~7 min end-to-end cracking on an RTX 4070 Ti.
More Explanation in their blog: outflank.nl/blog/2026/09/08/…
Github tool: github.com/outflanknl/ntlmra…
NTLMRain Table: lookup.ntlmrain.com
#NetNTLMv1
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). github.com/mubix/cyber-resum…
Rob Fuller retweeted
Open for work!
My stint at Roblox has ended.
Looking for interesting roles... if you know someone that is looking for someone with my skills, feel free to point them in my direction :)
Heard this fantastic quote today: “Mentorship is about making equals (or betters), not followers. If your mentee wants to be a follower it will never work. If your mentor just wants followers it will never work. Find someone that wants to be or to build an equal”
Rob Fuller retweeted
I built BloodBash to help me pass my OSCP+ with more confidence
It worked
The most surreal thing I experienced at DefCon 34 though was random people telling me they used it to pass their OSCP also.
If you have feedback please share it. I want to make it the best tool we can
@offsectraining @defcon #hacktheplanet #activedirectory #oscp #redteam #pentetrationtesting
github.com/SquidSec/BloodBas…
Rob Fuller retweeted
#x33fcon 2026 talks: @k3vinTell & @RWXstoned - DDD: DCOM, DotNet, Deserialization > youtu.be/lQD_Pz4IR5A
Introducing GLM-5.3: Built to Code. Ready for Cyber Defense.
- Top-tier coding and agentic capabilities, achieved through post-training on the 743B base model
- A major leap in cybersecurity, setting a new standard among open models
Tech Blog: z.ai/blog/glm-5.3
Rob Fuller retweeted
🚨 This one's nasty.
Googled "codex macbook download" — first result is a sponsored ad pointing to chatgpt.com. The real domain.
It opens a shared ChatGPT chat with friendly install steps: open Terminal, paste this command.
That command hides a base64 string. Decoded 👇
curl to trekmesh15[.]com — a known ClickFix domain dropping MacSync Stealer. Passwords, keychain, crypto wallets. Gone.
So the infection chain is: Google Ad → legit chatgpt.com share link → you infect yourself.
No exploit. No download. Just trust in a Google ad and a ChatGPT page.
Don't ever paste Terminal commands from an ad or a shared chat. Tell your Mac friends.