sneakerhax
@sneakerhax
Director of Red Team @Adobe / Previously, Red Team @Microsoft & @Intuit / Trendy Squid Life 🦑
Just to clarify the story of me breaking into Infosec: • I don't have any degree • I don't have any certifications • I wasn't directly mentored by anybody All I had was the freely available resources created by the community
RingReaper can easily bypass Linux Sophos EDR. src: github.com/MatheuZSecurit… Currently, using this technique is FUD against (what I've tested); - TrendMicro EDR - Cortex XDR - Sophos EDR #ringreaper #io_uring #malware #c2 #poc #edr
We're hiring a Senior Red Team Engineer @Adobe We're looking for an experienced Red Teamer to design, execute, and evolve Red and Purple Team operations Learn more and apply here: careers.adobe.com/us/en/job/R157…
Our Cyber Threat Management team is hiring a Staff Detection Engineer Join @Adobe and make the Red Team's life harder! adobe.wd5.myworkdayjobs.com/external_exper…
I'm thrilled to announce the Coming Soon of my offensive security game, Hack Back! After a year of development, I've released a blog introducing the project and game, which includes a link to Hack Back's Steam game page. Check it out! medium.com/@ty.anderson.3…
Updates to Tacticontainer! ⚙️📦 • Added Naabu and Httpx (Adding more weekly) • Added custom command arguments • Other QOL improvements The next step is to implement the experimental code for providing targets from file📜 github.com/sneakerhax/Tac…

Imagine you trigger a payload on a Red Team Operation, and some SOC Analyst sees { "data" : "😀🔥🚀🎂🐐🥂🚽💩" } paulbutler.org/2025/smuggling…
Your morning read: Our Red Team Assessment details activity against a federal civilian agency in early 2023. The assessment includes TTPs, associated network defense activity, recommended mitigations, and lessons learned to help orgs mitigate their risk: go.dhs.gov/3nP
I'm hiring a Senior Red Team Engineer! Join the @Adobe Red Team! If you have any questions, feel free to reach out. careers.adobe.com/us/en/job/R146…
Cybersecurity Red Teaming: When Assumptions Aren't Enough I am excited to share the article I published about our Red Team's capabilities, custom toolkit, and overall impact on @Adobe blog.developer.adobe.com/cybersecurity-…
I created a small pivot lab with Docker-compose. You can use this lab to teach pivoting, test pivoting tools, or expand it to support other internal services. github.com/sneakerhax/Ars…
Looking back at your code after focusing on being a manager for a year.
Ultra-Recon Update! Updated Ultra-Recon to support pulling remote source code for building images 📦 github.com/sneakerhax/Ult…

Something I’ve said repeatedly over the years is that cybersecurity is not a tech industry; it’s a media industry. 99% of the people involved talk about it and distribute information, while only 1% do actual technical work
The new @getpostman VSCode extension that was recently released includes the convenient generating code feature! You can quickly convert requests into code. This can be especially useful for more complex HTTP requests that include authorization, data, or headers Offensive…

Updated @feedly export Looking for a curated list of Offensive Security/Red Team resources? Importing this file into Feedly can help you get started or update a current feed list. github.com/sneakerhax/Ars…
New Github repo Arsenal-containers! Moving Arsenal containers into their own repo for automation purposes 📦 github.com/sneakerhax/Ars…
Red Team Interview Process Post Our Red Team intern wanted to better understand the interviewing process for Red Team jobs, so I put this post together. I'll add more questions over time. github.com/sneakerhax/Pos…
As the new Director of Offensive Security at Adobe, I officially own all the hacks! As a newish manager (<6 months), I wanted to ask other managers/directors what are your best leadership tips? Lastly, if anyone wants to chat, share, or compare notes, my inbox is open.
More random Kubernetes Goat stuff A bash oneliner for brute forcing directories with curl that you could use if you lack access to other tools.
