A Leader || Tech Expert || SOC Analyst || Digital-Forensic || ๐Ÿ’ป #BetterTogether

KE๐ŸŒ
Joined February 2021
HydraPWK: The Open-source security auditing toolkit based on Debian project designed and focused for industry realm, research, forensic, end point attack. hydrapwk.github.io/
4
42
1
264
h1lt3k retweeted
๐Ÿ”ต Ever wondered what the first year of becoming a SOC Analyst could look like? Weโ€™ve mapped it all out! This roadmap lays out a clear path for growth, showing what skills you can focus on month by month. Whether youโ€™re just starting out or looking for direction, itโ€™s a simple way to see what your journey could look like over a year. ๐Ÿ†• Ready to take the first step? Explore our NEW SOC L1 learning path today! tryhackme.com/path/outline/sโ€ฆ
7
42
2
326
h1lt3k retweeted
Burp AI ๐Ÿค Burp Intruder Generate and run Intruder attacks just by prompting Burp AI. It will make a quick list of payloads that you can run straight away or fine tune through Intruder.
1
24
152
0
COMMON CYBERSECURITY THREATS
1
77
1
502
h1lt3k retweeted
15 free cybersecurity tools
h1lt3k retweeted
CloudRip Fast Cloudflare bypass scanner Find real server IPs behind Cloudflare by scanning subdomains. Multi-threaded for speed, skips Cloudflare-owned IPs, supports custom or built-in wordlists, and exports results. Built-in rate limiting to avoid getting blocked REPO โคต๏ธ
h1lt3k retweeted
WAF bypass for XSS can be that simple, change the request method from GET to POST. The WAF was blocking the single quote we needed for an XSS payload, We managed to bypass by simply changing the request method from GET to POST which bypassed the WAF. #BugBounty #XSS
๐‘ญ๐’“๐’†๐’† ๐‘บ๐‘ฐ๐‘ฌ๐‘ด ๐‘ป๐’“๐’‚๐’Š๐’๐’Š๐’๐’ˆ & ๐‘ฏ๐’‚๐’๐’…๐’”-๐‘ถ๐’ ๐‘ณ๐’‚๐’ƒ๐’” ๐’‡๐’๐’“ ๐‘ช๐’š๐’ƒ๐’†๐’“๐’”๐’†๐’„๐’–๐’“๐’Š๐’•๐’š ๐‘ท๐’“๐’๐’‡๐’†๐’”๐’”๐’Š๐’๐’๐’‚๐’๐’”! Free SIEM Training Courses: Splunk Fundamentals 1 โ€“ Learn log analysis & dashboard creation. Link- lnkd.in/dipKnE7 Microsoft Sentinel Training โ€“ Cloud-based SIEM for monitoring. Link- lnkd.in/eq_2pKi2 Elastic Security Training โ€“ SIEM with ELK Stack. Link- elastic.co Free Hands-On SIEM Labs: TryHackMe - SOC Training โ€“ SIEM & log analysis challenges. Link- tryhackme.com ย Blue Team Labs Online (BTLO) โ€“ Advanced SIEM & threat-hunting scenarios. Link- lnkd.in/eUhPVhkE Security Onion Lab โ€“ Real-world SIEM setup. Link- lnkd.in/gtDenHkx
CYBERSECURITY: I BUILT A CLI APP THAT ENCRYPTS USERS DATA USING UUID AND VALIDATES USER THROUGH THEIR PASSWORD THIS PREVENTS HACKERS FROM ASSESSING STORE INFORMATION โ„น๏ธ
h1lt3k retweeted
SSTI-> Server Side Template injection {{ config.items() }} โ†’ leak โœ… Payload โ†’ Jinja/Django/โ€ฆ โ†’ unsanitized render โ†’ RCE potential Context-aware filter bypass required #BugBounty #SSTI #Infosec
h1lt3k retweeted
Want to learn XSS from scratch and turn it into real, practical skills? I made a 23-video YouTube playlist that takes you from basic payloads to advanced XSS chains โ€” with live target demos. Completely FREE. Watch the playlist piped.video/watch?v=1WFEVpyhโ€ฆ
3
97
654
24 Web application hacking tools
24
134
Web Application Penetration Testing Checklist๐Ÿ‘พ Credits: @e11i0t_4lders0n ๐Ÿ”—alike-lantern-72d.notion.sitโ€ฆ
3
102
498