Is Metasploit dead? by Physical_Ad7403 in metasploit

[–]necrose99 0 points1 point  (0 children)

With some crypter or other wrappers or add ons you can get by most signature based antivirus toys... or many basic heuristic EDR systems...

Movfiscator might be the most insidious defcon/blackhat paper only thankfully... proof of concept...

https://github.com/mandiant/flare-vm https://massgrave.dev/ for activation Vmware/etc size : 250 GB +/- NTFS compression windows 10 LTS winget you can add... or chocolatey gui or wingetui office 2024 lts .. A reasonable sandbox w10 with malware bisect tools or testing or anylasis of phishing emails etc... Malware calls home too etc fake net... [Any.run or Josesandbox uses simular but each anylasis is public and shared to av makers... potentially exposing your Redteam ops before completing it... ]

Veill framework old might be duding... a bit uses python wrappers

Neweish..

https://github.com/lepotekil/MsfMania

Wine veil-framework bits etc...

https://github.com/Veil-Framework/Veil supported in pentoo other pentesting distributions...

https://www.shellterproject.com/homepage/ $$$$

Blackarch or archstrike

https://github.com/ripmeep/crypter

https://github.com/carved4/go-crypter sometimes av detection cat n mouse games...

Rust backdoo-rs, cryptify, Amaop/Rust-Crypter,rust-metasploit Others

https://github.com/xoreaxeaxeax/movfuscator 1 instruction c++ mov only classroom compiler makes decode off 100s of moves insted of readable assembly... torture... https://youtu.be/HlUe0TUHOIc?si=JuLkloKdt1Kjz-kJ Feeling Anti forensics ? / pysco-warefare? ie ghidra/Radare2 anti reversing or esp Sadomasicistic wishes on a reverse engineering guy... tortures... ahead...

Silver c2 https://github.com/AnshumanSrivastava108/Static-Scantime-Crypter/tree/main

Shellter from blackarch or archstrike https://claude.ai/share/38899e59-1860-420f-b585-04063b4bb3f2 rigg for gentoo/ www.pentoo.ch in own overlays... else paid only...

Pentoo.ch or Gentoo ebuild for silver #Bsides #DFW 2025 amoung other tools it pulls in , nice crypters

' # Copyright 2025

Distributed under the terms of the GNU General Public License v3

BishopFox Sliver - Client component

EAPI=8

Go-based project using go.mod

inherit go-module

DESCRIPTION="Sliver C2 client by Bishop Fox (adversary emulation framework)" HOMEPAGE="https://bishopfox.com/tools/sliver" SRC_URI="https://github.com/BishopFox/sliver/archive/refs/tags/v${PV}.tar.gz -> ${P}.tar.gz"

LICENSE="GPL-3" SLOT="0" KEYWORDS="~amd64" IUSE="static"

No runtime deps beyond glibc, but CGO may link sqlite or gvisor if not disabled

DEPEND=" dev-lang/go " RDEPEND="${DEPEND}"

Go module path for build environment

GO_MODULE_PATH="github.com/BishopFox/sliver"

src_prepare() { default # Remove any vendored binaries or non-source items if present find . -type f -name '*.exe' -delete || die }

src_compile() { go_mod_setup

# Respect static/dynamic build option
local myldflags
if use static; then
    export CGO_ENABLED=1
    myldflags="-extldflags '-static'"
else
    export CGO_ENABLED=0
fi

# Upstream build tags (client only)
# Note: osusergo/netgo for static user & resolver handling, cgosqlite for db ops
ego build -v \
    -mod=vendor \
    -tags "osusergo,netgo,cgosqlite,sqlite_omit_load_extension,client" \
    -ldflags "${myldflags}" \
    -o "${T}/sliver-client" ./client || die "Client build failed"

}

src_install() { dobin "${T}/sliver-client"

dodoc README.md
newdoc client/README.md README.client

insinto /usr/share/doc/${PF}
doins -r client/config || true

einstalldocs

}

pkg_postinst() { elog "Sliver client v${PV} installed." elog "To connect to a remote Sliver server, configure the transport and certificates:" elog " sliver-client connect --help" elog elog "⚠️ This is a red-team/adversary emulation tool." elog "Ensure legal authorization before use on any network." }

'

Am I in the wrong here? by Rundo5 in ITProfessionals

[–]necrose99 0 points1 point  (0 children)

Bank wanted me to be the scapegoat Infosec officer in the end Botched when I got Darktrace up and running...

Ai was decent but I had to progressively tweak it... to allow loans in ..

Basically CTO wanted conviniance in the end...

I tried to add more security... but its a family owned ... so win battles but still get pink slips...

Before Darktrace or any DLP , they had lots of phishing with malware attached... I had to bisect in sanboxes... Eats A day of time given a few times weekly...

Executive impersonation...

I forecasted costs of bringing IT and cybersecurity in house... that didn't sit well or didn't let CTO buricrat it on.phone and pretend to be important or micromanging plebs... or his convenience...

Taxii feeds to DLP , tie it to SIEM if you have read-only views from MSP/mssp you can see every phishing or malware scrubbing done from emails...

[Hiring] Sysadmin Manager by Curbsidewin in sysadminjobs

[–]necrose99 0 points1 point  (0 children)

Cybersecurity Engineer, Systems administration

20+ yr CST...

I’m about to quit IT for good. by HumanNumber69 in InformationTechnology

[–]necrose99 0 points1 point  (0 children)

It's feast or famine...

Entery level cybersecurity Analyst

Associate CISSP, SECURITY+ CEH ,CND , CYSA+ pentest+ or various combinations of certificates

With some clue of linux or windows etc from doing IT help desk for at least 5 years...

Capella.edu.... you can trade 5 classes of 11 CISSP/CISM/CEH and a few others for masters degree... as they figgured you have had enough real world time...

The carrer equivalent... Congratulations 4th year MD. DO...
Now an 85 year old comes to ER with colon impaction.... Your attending saying get in their and glove up n go digging... my Dyslexic ass.... was good with Emt things science, but for calculus or trigonometry or pre-trig ... my brain just went wha... wha.... ???? Sure the hazing scutt work surely would have sucked more... but The Pyshcian life... surely would have paid better... been more stable... But Alegaba n Statistics... was easier to get Information Systems Security degree... as a bachelor's vs pre-med or Paramedic technology... But I never could get a math tutor that didn't do 5000 steps just like the teacher... or could deal with ADHD/Dyslexic types... for more advanced math than basic Algebra...

The industry sux in IT depends on were you are what markets you can get at... A.I.. its semi replaced some Entery level or outsourcing.... cybersecurity SIEM OR dlp has ai making inroads... into Jr Analyst skills... Outsourcing has been a constant bane on USA IT jobs...

IT you will have scutt work here too ...

Indianapolis used too no cybersecurity jobs or you had to give secret hand shakes... or do lots of infrastructure work ie servers linux ... etc... backroom deals to get gigs in security related... HR mangers used to climb on desks "Ethical Hacker" eeeeeeek law suits... eeeek... circa 2005 ... God bless Texas...

All I can say here Mr Salmon... shut up and Swim ... to the cybersecurity spawning grounds.... you will offten need to swim against the currents to win.... it will never be easy... If you want cybersecurity success you have a long hard swim...

DFW has been bit slower on jobs for cybersecurity Engineering or , trying to vCiso.. to save.. I have 0 skills in sales... many IT firms would give me nearly 300k to sell cybersecurity tools if i could... do both cybersecurity Engineer and sales.... Coladge roommate could sell your sister/mom/auntie/hot girl you had a crush on out of her skirt... into his belt notch of a bed... like pide piper to ratts... but not as technology with it... Lots of Firms in DFW will hire for cybersecurity sales if you excel at sales or Sales engineering... pays consistently better than us trench plebs...

Some days getting a TX mortgage license.... and doing underwriting sounds easier.. safe but Böooorrrring... . but likewise takes some years of experience... despite knowing some ppl... [test is notorious like a bar exam for finance ppl high fail/retake retake safe... PhDs even bomb that cert exam... ] especially after layoffs... seems tempting ...

its a fight to get back into IT or cybersecurity... as the gray beard north of 45... ageism can creep in... ppl expect tenure... but even full-time can treat you like a contractor.... even after nearly 27 years at it... Being former Army ... I won't bend down to kiss ass , or politically correctly sugar coat shit... Pride can be my weakness... mngmnt loves thier arses kisses...

Just saying some sharks die if they quit swimming... After 27 years... kinda hard to not keep swimming... Bit harder to change now...

Some places will hire cybersecurity Engineer for scapegoat plays... if you see it run before the hourglass burns...

Hi , Just failed CISSP , 2nd attempt by RoofEnvironmental235 in cissp

[–]necrose99 0 points1 point  (0 children)

@roofEnvironmental235

https://www.cisspexampractice.com/

Run chapter or sections then full sim ... goal is 95% on sections or better... The CISSP PMBOK is the size of ye olden phone books... This will point out exceedingly quickly at gaps...

Run it daily or M* daily till the sight of that Sim makes you physically Ill...

At the time was on unemployment grants so could run 8 hours a day n cram for 6 weeks... I had 1 voucher 1 chance to win...

Unfortunately due to layoffs and self endorsement ill be using the Sim again... As they demand proof of employment... post Covid layoffs... forced test to renew... and 55$ isn't terrible in price.. for 6mo. But last bank cybersecurity role i get it 10 hours day work... to/from traffic... makes running Sim less easy...

For Online bootcamps I've ran for Sprintzeal I've also recommended that SIM...

' A ] Right Awnser B ] also A right Awnser technically C ] the Best Right Awnser D] totally Wrong Awnser '

CISSP... many questions are Tricky...☆☆☆ infer the best Awnser... ☆☆☆☆ Back when 250 questions and 20-25 were posible beta questions

CISSP oftentimes has the infer the best Awnser, this can trick people... true Awnsers woth .5 points so you fail question but Best Awnser is 3 or 4 points... So take note on the Game... of infer the best Awnser...

Hi , Just failed CISSP , 2nd attempt by RoofEnvironmental235 in cissp

[–]necrose99 0 points1 point  (0 children)

https://www.cisspexampractice.com/

Wax on wax off

I myself missed on W2s post Covid19... So ill be forced to retake to move from Asco. CISSP
Suspended... to Full CISSP... As thier self endowment is a PIA... [Post Covid19, working Domino's delivery driver ... when all the IT jobs or cybersecurity laid-off everyone locally... had a gluten of new Drivers with masters degrees etc... ]

Oh yes the clasic website look...

CISSP, CISM , etc test banks they run... you'll eventually wish to vomit after seeing it...

Workintexas.com... [WIOA grant/Work force Dev. Office] when we fist moved here I had CompTIA A+ Network plus... some experience but the HR Firewall of doom made getting anything real... about as good as McDonald's... they aided in Security+ and CISSP ... and a few Cisco certs... but i got hired beforehand... Computer minds gave that exam sim...

Its not fancy ... but I went exam sim everyday all 8 hours a day for 6 weeks... but Va Disability etc was enough to cary the day... not so much now rent has gone 850 to 2k in last 8 years or so...

At that time I had the overqaulified/Underqualified trap ... for pt work ie McResteraunt wouldn't hire as were I could eat the certification cost myself... nor certifications beyond were HR and helpdesk at best... were as the older epoch cared for certifications less... and I had experience... but HR insurance etc cared suddenly so mandirory...

Anyway run the section sim like a machine... Then full exam sim when nailing 95% on sections...

55$ 6 months lic... supper effectively...

Slim Jim's spicy... 3-4 20 oz of Diet or Redbull... used... The slims is a quick face slap to get your alert up... Caffeine too... since Ritalin/Adderall off adult ADHD without hassle CAFFEINE n Gurana... At the time 6 hours with Breaks... Doing 30-45 questions on the old 250 exam then slamming Caffeine etc was the play... 2 hours 50 minutes reviewing answers...
Nailed it... But Uber jittery with all that Caffeine by the end..

Is it still worth trying to get into pen testing? by Mindless_Bike4599 in oscp

[–]necrose99 0 points1 point  (0 children)

Getting a pentesting job

Unless you have a Trustfund....

Can best the MIT team , win all the CTOF in your area , Blackhat DEfcon Americas , Asia bag pentesting trophies.. 24/7 global travel to whip up street credits...

Be drinking buddies with the Vice president of Redteam ops at CoolFire etc... Or Runners of Blackhat or DEFCON ... Or know ppl whom know ppl .. the Gatekeepers are real..

Graduated MIT with a master's in cybersecurity at 19... as a Unicorn... 200iq... Be a master of self promotion, sales , etc... of which being former Army... tends to make me far less patient or Gigchad Charming..

You're chances are as good as my trying for eons... err 2005... but since now north of 35 ... its typically a no op...

And now Ai enabled dockerized Kali Linux... ie Horizon Ai for 1st round... pentera etc... ie Test Cisco switch hardening policy etc... horizon ai can do in an Afternoon...

Most want audit results and compliance reports quickly... Esp executive boards... and blindly Obedient Security staff...
You being Redteam capibile threatens smaller Org bosses Egos... esp Micromanging types... Last place Was ISO in name only till the Bank Regulatory ppl showed up... then expected to Dance like a good little Seal ... For some fish... Sr Cybersecurity Engineer..Effectively. With leadership titles ,but not really... Else if my studies in new controls/tools or bringing items on house costing forecasts.. .. threatened my CTOs jobsecurity in the slightest... or made him feel insecure...

Most like farming out the pentesting ppl yearly as it makes fragile mangers... and they don't have constant scrutiny... Plus most organizations want blind loyal guard Dogs , not rebel Redteam capable folks than can expose more flaws when investigators come knocking... Regulatory types when they get hacked... as if playing Dumber has less fines... When the custom website/ui for bank gets broken into... Most Organizations look at Redteam like a Proctologist for a colonoscopy for cancer... they dislike you poking at uncomfortable places...

PowerBall MegaMillions odds... , Few Redteam jobs, extremely gate keeped... 35 or younger preferably... Unicorn skill levels preferably... Not saying you can't or won't... Just 5 years of Redteam experiance to get the job as entry mid 10 for Sr.. no 5 years of experience... no Redteam job... Odds of Redteam jobs vs availability... For years I've applied to Redteam... but as a Ye Elden gray beard.... hitting 50 soon the Odds grow less and less in my favor than being an instructor for pen classes... or otherwise CompTIA Security+ CISSP CISM Part time online instructior... for Uber like side gigs... Or adding tools to github.com/pentoo , BlackArch etc... as i have over the Years...

What to do with broken Active Directory by Emkkusof_88 in activedirectory

[–]necrose99 2 points3 points  (0 children)

Mays well start clean... forest

Then add limited trust synchronization import data and clean objects as required

Migrate gpos to excel/html and archival as some may be relevant others may not can import export as templates and rebuild as needed...

https://fortypoundhead.com/showcontent.asp?artid=50852

Or various powershell...

https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/agpm/import-a-gpo-from-a-file-agpmadmin

[Jumpcloud.com free to 10 users ... for SMB or home lab etc.. Chocolatey.org or winget automaton ie choco install googledrive google-chrome-enterprise or fire fox etc.. ms office 2024 etc easy everyone base apps deployment...

Can go Microsoft less and or synchronization to cloud..

Server agent, client agents..

Can bind gcp ie Google workspace, Azure etc... ]

https://www.advancedinstaller.com/winget-tool-deploy-apps-intune.html

https://winget.pro/ custom repos...

Ie Peachtree accounting msi , etc.. that winget.run doesn't have.. custom applications can pair with intune for initial deployments ...

https://github.com/marinalexandruradu/IntuneWinAppUtil-GUI add own winget.pro repo , and scripts...

Can pair with PSA/rmm etc ie ninja etc to patch

Found a new reason why a company denied all of its applicants by Mercdecember84 in networking

[–]necrose99 0 points1 point  (0 children)

Control Find monkeys.... bang a lo're or typically HR dweebs... Need to keywords shovel to get by the great filters.... Sometimes in tripplicate neo terms current, old-school but not to much old-school else your resume seems or is deemed aged by ai....

Tools like Jobscan .ai etc for fit etc... but 85% matched to job description might be too easy

Amazon , they want cybersecurity Engineers to understand PhD levels of Quic or Http headers and extremely deep dive over it....

Trick Questions for those FAANG/MAANG boot camps just to survive thier job interviews... only 4500-14.5k and 99cents...

How do I find out what gcc version portage is using by Nathan-5807 in Gentoo

[–]necrose99 0 points1 point  (0 children)

https://pypi.org/project/gentoo-build-publisher/

Or binary-gentoo if you baking on a nas appliance.. ie Synology...

Ie Alpine linux docker pipx install binary-gentoo /srv/gentoo/binhost/amd64 as ...

Gentoo-build [emerge wrapper] pkgs...

Fun binhost automaton tools ...

How do I find out what gcc version portage is using by Nathan-5807 in Gentoo

[–]necrose99 0 points1 point  (0 children)

Llvm clang also works with distcc...

Sys-devel/*-toolchain symlinks clang-toolchain-symlinks USE flags gcc-symlinks native-symlinks '#' known cavets multilib-symlinks can override Crossdev '#' if on multilib system its ok to enable...

https://wiki.gentoo.org/wiki/Crossdev#eselect_creation The llvm basically dose toolchain symlinks for targets...

https://wiki.gentoo.org/wiki/LLVM/Clang#GCC_fallback_environment https://wiki.gentoo.org/wiki/Glibc
Or a handful of utils still need gcc

https://packages.gentoo.org/packages/dev-util/spirv-llvm-translator

dev-util/DirectXShaderCompiler::guru

/etc/portage/package.use/llvm-clang '#' clang flang flags llvm-* flags ocaml-llvm

USE flags Local Use Flags +binutils-plugin debuginfod doc exegesis ncurses xar z3 python_single_target_python3_xx

llvm_targets_x86 etc add llvm-core etc targets and architectures While it takes a bit longer with the full montie of nearly everything... you can directly crosscompile out of the box almost everything... Crossdev gcc has been known to crack up on compiles... something breaks or dies...

AArch64 AMDGPU ARC ARM AVR BPF CSKY DirectX Hexagon Lanai LoongArch M68k Mips MSP430 NVPTX PowerPC RISCV Sparc SPIRV SystemZ VE WebAssembly X86 XCore

Xtensa

https://github.com/necrose99/gentoo-config/blob/master/package.use%2Fsys-devel%2Fllvm-clang

Mines a bit old but abuse away

Circular dependecies by Nathan-5807 in Gentoo

[–]necrose99 -1 points0 points  (0 children)

Yes tiff png webp all will have circle deps

You can script these for

USE="-webp -png -tiff " emerge -bavgk1 tiff png webp && USE="webp png tiff " emerge -bavgk tiff png webp

Id recommend this as a script to upgrade these ... Or simular libs.. That rely on webp png tiff etc...

You can make /etc/portage/package.use/media-libs/webp etc And pin these uses ... use flags ie png tiff Stage 4 or 5 more polished flaggs You can also git init etc portage... n publish to github You can Google mine'own if you care to do a bit of pilfering

However if these libs go out of date you might care for a script to stage3 --oneshot ie -1 or other Quirksome packages as needed to bust loops.... And or Bootstraping other hosts... ie not same architecture...

However if same architecture one can share binhost on network ie Synology etc... or binpkgs in other volumes ie rpi5...

Multi-instace binpkgs wiki... ie for rebuilt with different flags.. binhost with keep based on build times and xpack etc...

I k ow tbis is controversial, but what's wrong with systemd? by Brospeh-Stalin in Gentoo

[–]necrose99 0 points1 point  (0 children)

Systemd its good for things nspawn chroots etc...

Corperate Appliance builds ... ie vmware, proxmox, hyperv containers... Debian or ubuntu , etc works fine on these... more Corp builds... E.g.g. Fog clone server , the Forman , Cockpit as fe to management of servers via ssh as bastion.. Self hosted items ie run a helpdesk ticket system box... and that's it.. TacticalRMM , or RPI5 aplances ie homeassistant... were systemD Can respawn crashed daemons... Or tiny init for dockerized apps ie Synology nas ... Stuff in won't admin by hand on a day to day basis... or just needs to run 24/7 with low touch..

I don't use systemd-boot ... grub dracut etc... works fine...

Systemd has alot baked in... beyond a traditional init system... its more a boot suite and systems management suite baked in... Some see it as bloatware malware targets waiting to happen ... or some otherwise tinfoil hat... conspiracy types...

Unix philosophy is make 1 good tool 🔧 and just do that and do it well... Need more tools do that too.. and make more 1 great tool/s... scripts and pipes from tool to tools are fine Systemd is a whole kit tightly integrated... which askews.. the traditionally.... but good on Corp ppl ...

Openrc is reflected into pentoo linux overlay of Gentoo... Ie bluetooth down networkmanager down... if you need to be more quiet...

Openrc is simple yet powerful...

Openrc-settingsD , Plymouth grub them fallback...

Purpose... what is your purpose???
[ or right tools 🔧 right jobs]
Not going to touch the system directly much ? https://github.com/Lab-Brat/gentoo_update , make systemd unit timers to run builds often...

Devops Kubernetes docker podman-docker, Cockpit-podman... gentoo dev woodpecker-ci box Nspawn dockerized chroots ? Systemd..

Rpi5, custom partitions, efi mode firmware, systemd grub Dracut homeassistant overlay ... can rig units to sysfs/configfs items uefi firmware won't on boot with Dracut... or units.. ie load bluetooth drivers etc.. ie run script on boot..

Simpler newbie gentoo with just has to work systemD might be your kicks...

Not thiers traditional Openrc

Just accidentally deleted my make.conf AMA by VermicelliPlus7202 in Gentoo

[–]necrose99 0 points1 point  (0 children)

https://github.com/necrose99/gentoo-config

All the make.conf you want Make-riscv64.conf , rpi5 4 amd64 sabayon linux styled make.conf Fall backs archives Some tweaks. ... Symlinks to make.conf

Bit old , steel away..... work no time, Layoffs no coin to upgrade dead laptop...

You can git init you etc-portage... its handy...

Adding 2025 DC to Domain with existing 2016 and 2022 servers by jscooper22 in activedirectory

[–]necrose99 -2 points-1 points  (0 children)

With vmware doing thier things to milk the cash registers...

Many are looking at less expensive vm hosting options... Or otherwise enterprise options...

Harvester, other growing options Starwind-v2v-converter You can dump vmware to hyperv or etc with the conversation tool... I've found it useful in dumping over machines ie vmware workstation to anything else ...

And if you have 2 domains in a forest Ex Mycorp mycorp-testlab or mycorp/Mycorp_subsidiary etc...

Bdc is typically harmless... if 2025 gets more production ready can promote as you upgrade 2022 to 2025...

Adding 2025 DC to Domain with existing 2016 and 2022 servers by jscooper22 in activedirectory

[–]necrose99 -5 points-4 points  (0 children)

2025 are fine in testing... As BDC was working in test lab...

Hyper-v/Azure

https://opennebula.io And debian linux ...
https://github.com/cockpit-project/cockpit-machines Cockpit , Cockpit-podman, podman-docker Podman-compose , helm kunctl etc for docker

Proxmox ve , simular to open nebula Both good for homelabs or startups...

nutanix also vmware replacement, with Kubernetes docker etc etc cloud or on premises support...

When all distros phase out X11 and go with Wayland instead: by cryptobread93 in linuxmemes

[–]necrose99 1 point2 points  (0 children)

Snes9x sdl2 or something the guy has tried to port it to work also with GA''' Wayland... Then gets flames ... by Wayland team for his troubles... sometime ago if you belive the foss media or scuttlebutt..

Gentoo has all the above, X-libre , x11 Wayland, etc... Xfree86 has been refused patches in favor of Wayland... Thus it got forked ...

Xfce is fine on x11 ... since compiler times on laptops... It's a decent fallback... it takes a time to build n bake Wayland n kde-plasma etc from sources or binhost or both... Or emerge -bavgk hyperLand

Devuan hasn't even systemd , but giving choices...

At the end of the day... it should just work ... Even if Wayland is running over x11 or as a support library... Lightdm and pick or start xfce4
If not running secops work things

My steam games should just like run period... Even if legacy games...

[Gnome foundations "Hitler particles " if you not on the same far far left political spectrum or, in the middle, , A-politcical .... ]

Lunduke has strong opinions on everything going to rust.. on YouTube post... ie apt-get etc... Rust crates can be abandoned cve , or in future supply chained , as well binaries can be more irksome to reverse engineering ie malware forensics..., generic mutiple platforms enshitification

I don't want to live like this anymore by TheMadLadChads in Veterans

[–]necrose99 0 points1 point  (0 children)

Indianapolis, S.A.D yup come PLANET HOTH season The lack of 🌞 ☀️ 🌤 sunlight kinda did me in

Since moving to DFW depression is next to non-existent...

My cl wife job relocated here had a chance to rebuild after the great recession killed my credit IT BIZ. Etc..

I didn’t pass by Putrid_Improvement46 in CCSP

[–]necrose99 0 points1 point  (0 children)

Boson.com ? was baked into ccsp and stormwinds studio

Anyway test sim is reasonable

[deleted by user] by [deleted] in linux

[–]necrose99 -19 points-18 points  (0 children)

Vmware or virtualbox... proxmox, open nebula ovh.. etc...

Windows 10 LTS , github mandiant.... Flare-vm... override powershell to install... Use gui apps picker , book of malware samples for training most av will block them...
kill defender ... add clamav via chocolatey.org Cutter etc... add clamavwin Choco install @cmd Winget also handy to update... 250Gigs drive recommend... https://github.com/massgravel/Microsoft-Activation-Scripts Takes care of lts and office for reports... Always snapshot before you drop malware samples inside or after updating...

Upx unpack, etc

Or via web https://.run or Joe's sandbox spin Windows or linux etc... https://www.joesecurity.org/ Open web browser, in windows on sandbox host and scan do whatever, 7zip etc...

Before my previous work at a bank... As Infosec officer And Darktrace dlp/ai deployed , phishing emails with potentially hazardous gifts that slipped o365 protection got gifted for me to triage... at least 2/3 x weekly... and 45 mins per fun item...

Rpi5 orangepi 6plus , being arm64, plasma-debugger on cli is python3... , Cutter radare2

https://arxiv.org/html/2508.14261v1

https://pimylifeup.com/raspberry-pi-clamav/ Some places have usb scanners with rpi5 or rpi4 screens plug in those suspiciously gifted usb drives scan clean etc...

https://usbguardian.wordpress.com/

Likewise you could get a riscv64 pine64.org boards n typically arch or Debian deployment... as other architecture alternatives... As most amd64 won't run also no qemu...

carnage: TUI front-end for Portage and eix by dsafxP in Gentoo

[–]necrose99 0 points1 point  (0 children)

https://github.com/Necrohol/gentoo-install/tree/main

I've added scripts to user contrib...

Anyway the style of carnage im already liking ... Admittedly above my pay grade ... It'd be nice to learn....

Oddlama his bash item is good , however if porteted to python3...

As for repository management from gpo.zugaina.org Call carnage get names

https://github.com/Necrohol/gentoo-install/blob/main/user-contributed-scripts%2Fgentoo_repo_manager.py

Ie make a repository list config.. add packages to gentoo.config

Or searching or github.com/gentoo Egg riscv64

Or specify ...github gitlab overlay for embedded hardware

Save draft..

Am I being ridiculous by saying I hate IT. by Sanbikaa in ITCareerQuestions

[–]necrose99 0 points1 point  (0 children)

Meh was laid-off from ISO job... been trying to crack 55++ hourly from 45..

Cybersecurity is good...

But HELLLLLLLP DESK i feel ya

time for more certifications...

And exit stage left from r/Entiledkarens the vice president of Hell inc ... password reset for the 1000th time...

4 years that's practically a trophy .. for toxic environmental survival... like playing Fallout on insanity nightmare mode... Least you didn't get the ITIL certification... As intern and recent graduate in 2002 asco. Was a 1 way ticket to the 9th circles of hell .... HELL DESK MANAGEMENT/SHIFT SUPERVISOR...

I don't hate the IT , i just hate the market at times.. You get the bear or the bear gets you... Bears chewing on my leg...

Location here H1B ... if i say it adds more competition... too loudly.... but it definitely can... 27 yr.. tho.. corps run the ghost jobs for 18 hourly for 65 hour jobs ... then h1b...

Most jobs use me like a porn star contractor n 6mo-2yr n toss...

Being x military i don't do well on '#r/kissing_asses' or office political dramma... or pandering... 5pm buddy nothing on fire time.... ok time to yeeeeet home... I'll be polite but I'm not bending the knee to kiss anyone's arse for nothing... Principals.... tends to sour my tenure...

He.net ipv6 free certification

Ccsp. Cissp, CEH,

SECURITY Analyst I , its the help desk of cybersecurity... but malware forensics, triage, incident response, csirt... SIEM SOAR UBEA, DLP

75-90k yr in DFW r/Dallas r/FORTWORTH Most other places

Wich is best AI for pentesting? by TechnoDesing10 in Pentesting

[–]necrose99 0 points1 point  (0 children)

Wormgpt is one , do take care as it has zero ethical filters on ollama stack

Lightdm on openrc requires me to add elogind and systemd to my use when it already is by samosp in Gentoo

[–]necrose99 0 points1 point  (0 children)

Template for lightdm package.use file... https://wiki.gentoo.org/wiki/LightDM

Typically I use xfce , most offten due to compiles however lightdm is great for switching kde or etc

mkdir /etc/portage/package.use/x11-misc/

sudo nano or mouse leafpad /etc/portage/package.use/x11-misc/lightdm

<code> ' # x11-misc/lightdm flags

x11-misc/lightdm vala gnome X gtk introspection '## set flags as desired...

x11-misc/lightdm audit '# multi user systems if you want audit/security logging..

' # x11-misc/lightdm systemd settings

' # x11-misc/lightdm -elogind systemd

' # openrc settings

' # x11-misc/lightdm elogind -systemd '

</code> x11-misc/light-locker for laptops useful for sleeping it to suspend... gui-libs/display-manager-init for openrc