Log inSign up
Mike Felch (Stay Ready)
9,301 posts
user avatar
Mike Felch (Stay Ready)
@ustayready
Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
USA
Joined July 2013
1,935
Following
17.1K
Followers
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Nov 20, 2018
    “Dad, I need hacker stickers on my laptop.” says 5yr old daughter.. she went through my stash and selected what she wanted lol
    Image
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Dec 21, 2023
    Twitter has a "like" bug that lets you artificially inflate by repeatedly clicking the like button. Wrote quick POC, just copy the xpath from the heart of a tweet and paste in chrome console: for (var i = 0; i < 100; i++) { var hax = document.evaluate(COPIED_XPATH, document,
    Image
    user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Dec 21, 2023
    Wow this is popular.
    545K
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Sep 2, 2023
    Full disk encryption bypass and root shell on TPM-protected Ubuntu 20.04…by pressing enter multiple times really fast.
    user avatar
    Sí, soy yo
    @nuria_imeq
    Sep 1, 2023
    Mashing Enter to bypass full disk encryption with TPM, Clevis, dracut and systemd pulsesecurity.co.nz/advisories/tpm…
    pulsesecurity.co.nz
    Mashing Enter to bypass full disk encryption with TPM, Clevis, dracut and systemd
    This vulnerability allows a physically-present attacker to control the full disk encryption unlock process and gain complete access to decrypted content in some cases where a TPM, dracut and Clevis...
    335K
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Nov 30, 2022
    Want to create great phishing links using an open-redirect on google.com? While they don't last forever, they are a great way to trick unsuspecting victims into clicking a legit looking URL before expiring! gist.github.com/ustayready/3ba… Follow the 🧵for how it works..
    Image
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Feb 28, 2022
    Dropping a new initial access technique via RDP that I dubbed "Rogue RDP". Use malicious .RDP files to bypass email/servers/security gateways and then run code to binary plant/exfil from your own RDP server, blinding EDR. Bonus: Target runs HyperV? RCE!
    Image
    Rogue RDP – Revisiting Initial Access Methods - Black Hills Information Security, Inc.
    From blackhillsinfosec.com
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Oct 31, 2022
    A quick method to bypass an EDR. Even aggressive EDR's can be bypassed. Allocate your shellcode, overwrite a WNF subscription callback in a userland process, and trigger the WNF state change.. Old but relevant example github.com/ustayready/wnf… follow for more fun soon to come!
    Image
    GitHub - ustayready/wnfexec: WNF Code Execution Library Using C#
    From github.com
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Jul 3, 2019
    I got caught hacking the Buzz Lightyear ride at Disney by the in-game cameras. I was tired of my wife beating me every time so I took a picture of the high value target and repeatedly shot the picture on my phone. I had the idea too late to win but it’s game on next time! 🤓
    Image
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Apr 1, 2019
    FireProx has been released! If you're tired of using limited proxy servers or expensive EC2/VPS instances for rotating IP addresses then check out FireProx. It spins up a pass-through API Gateway proxy on AWS which will rotate your IP with every request!
    Image
    GitHub - ustayready/fireprox: AWS API Gateway management tool for creating on the fly HTTP pass-t...
    From github.com
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Dec 5, 2022
    Black Hat USA 2022 videos are released! youtube.com/playlist?list=…
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Dec 16, 2022
    New process injection technique dropped from BlackHat EU! Freaking cool. Dirty Vanity abuses the Windows forking (process reflection and snapshotting) to evade EDR using. Slides: i.blackhat.com/EU-22/Thursday… POC: github.com/deepinstinct/D… Shout-out to @eliran_nissan!
    56K
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Mar 4, 2020
    Healthy reminder: there are troves of amazing infosec people that you have never heard of because they don’t speak at conferences or have a platform on Twitter... like troves..
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Jul 19, 2024
    CrowdStrike has some of the most sophisticated technology and smartest engineers I've ever known. I've seen the inside of the sensor and read through lots of eng docs when I worked there, it's just a simple mistake with huge ramifications.
    74K
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Aug 5, 2019
    If you gain access to a company GitHub, look for <filename>.PublishSettings (don't forget commit history) and you might just find access to Microsoft Azure resources in plain-text. #azure #redteam
  • user avatar
    Mike Felch (Stay Ready)
    @ustayready
    Dec 6, 2022
    Freaking cool open source real-time HTTP intrusion detection (logging, monitoring, and alerting) in the console
    Image
    GitHub - teler-sh/teler: Real-time HTTP Intrusion Detection
    From github.com

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement