Log inSign up
Vincent Yiu
36.7K posts
user avatar
Vincent Yiu
@vysecurity
Director, Red Team / Offensive Security. Help organizations safeguard their businesses from the bad guys.
Hong Kong
Joined December 2014
352
Following
31.7K
Followers
  • 已置顶
    user avatar
    Vincent Yiu
    @vysecurity
    1月15日
    In case you missed it: Add a colon to your password, ":", because all the stealer logs have colons, so it'll end up splitting your password incorrectly.
    5K
  • user avatar
    Vincent Yiu
    @vysecurity
    2018年4月10日
    Took all those "Red Team Tips" and stuck it onto one page: vincentyiu.co.uk/red-team-tips/ I'll update this page occasionally #redteam #adversarysimulation #cyber Also, I want to add that there's some duplicate numbering :( Ah well...
  • user avatar
    Vincent Yiu
    @vysecurity
    2021年5月9日
    Sent a PR to EDRs hook repository to visualize and quickly reference which APIs are hooked. github.com/Mr-Un1k0d3r/ED…
  • user avatar
    Vincent Yiu
    @vysecurity
    2024年3月6日
    The fuck, what kind of vulnerability is CVE-2023–24044? You can modify the host header so that it redirects to the attacker's domain instead. What is this bullshit? How did it even get a CVE?
    CVE-2023–24044
    From medium.com
    184K
  • user avatar
    Vincent Yiu
    @vysecurity
    2022年1月19日
    What do people do with 64 GB RAM on a laptop?
  • user avatar
    Vincent Yiu
    @vysecurity
    2017年9月13日
    Exploit CVE-2017-8759 without Macros or any interaction. Simply click on the infected file and boom code execution. github.com/vysec/CVE-2017…
  • user avatar
    Vincent Yiu
    @vysecurity
    2023年5月21日
    Replying to @ianmiles
    Just floor him. Why’s the guy wasting time?
    111K
  • user avatar
    Vincent Yiu
    @vysecurity
    2018年9月17日
    Red tip #333: One liner to grab all cleartext WiFi passwords: pastebin.com/MuUdJaG7
  • user avatar
    Vincent Yiu
    @vysecurity
    2022年12月6日
    Common persistence mechanisms for Linux /etc/rc.local /etc/init.d/ /etc/profile /etc/crontab /etc/cron.d/ /etc/cron.hourly/ /etc/cron.daily/ /etc/cron.weekly/ /etc/cron.monthly/ /etc/cron.yearly/ Startup Applications Systemd Services .bashrc .bash_profile .bash_logout
  • user avatar
    Vincent Yiu
    @vysecurity
    2023年1月17日
    What on Earth do people do with 96GB RAM? Open like 32 instances of BloodHound neo4j databases?
    182K
  • user avatar
    Vincent Yiu
    @vysecurity
    2021年2月20日
    Red Tip #434: SSH Agent Forwarding can be exploited to advance your presence on a network without SSH keys or passwords. @int0x08 has an example command snippet available at gist.github.com/int0x80/9e7b09…. Great for when you have a shell but no credentials. #redteam #cyber #sshagent
  • user avatar
    Vincent Yiu
    @vysecurity
    2022年5月5日
    When you need a calculator do you just type Python3?
  • user avatar
    Vincent Yiu
    @vysecurity
    2025年9月3日
    Turns out many Red Teamers and Penetration Testers were exploiting this as a zero day for the past decade 😂
    54.4K
  • user avatar
    Vincent Yiu
    @vysecurity
    2023年2月10日
    Red Team 2.0 appears to become: 1) Give a machine on the internal network because phish fail. 2) Disable EDR because can't seem to bypass the EDR. 3) Can't figure out how to pivot network segment. 4) ... Dude, why not just ask to be put on the core banking system?
    139K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up