TGViewer
Channel Public Channel
Gravity's Rainbow

Gravity's Rainbow

@gravity_rainbow

Cooking cybersecurity stuff.

News, tools, jobs and articles.

No bullshit. No fluff. No auto-AI generated.
Subscribers
34
Photos
10
Videos
0
Links
11
Recent Posts 13 shown
Post #14 96
[ WinSSHound ]

Windows SSH Misconfiguration Discovery Tool - Map lateral movement paths through misconfigured SSH services in Active Directory environments

https://github.com/1r0BIT/WinSSHound
Post #13 123
Nowadays, I tend to post less, not more. Mostly, due to recent events in Cybersecurity and all the technical world.

However, if there is only one post that you need to read choosing across all 999 AI hot takes and marketing bullshit, read this:

Technical report released: The AI-Assisted Breach of Mexico’s Government Infrastructure

https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report

Welcome to a new world, with PetitPotam and Claude in one technical article.
gambit.security A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report Gambit's full technical report on how a single operator used two AI platforms to compromise nine government agencies, expanding our Mexico findings.
Post #11 592
#htb #cert

[ HTB Certified Offensive AI Expert - HTB COAE ]

You will work through hands-on labs that focus on how attackers actually target AI environments: adversarial ML, data poisoning, evasion attacks, LLM output exploitation, and AI privacy breaches. No theoretical simulations here; you will be performing professional-grade assessments on realistic infrastructure.

Meet the new HTB certificate: https://academy.hackthebox.com/news/the-new-htb-certified-offensive-ai-expert-htb-coae-is-officially-here
Post #10 82
#network #ad

[ Active Directory Attack Architecture Map v1.1 ]

Contains:
- Active Directory Basics for Beginners
- Attack Flow Chains
- Kerberos Fundamentals
- NTLM Authentication Basics
- Credential Dumping Deep Dive
... and more!


https://kypvas.github.io/ad_attack_architecture
  • 👍 1
Post #9 69
#web #jwt

[ Keys to JWT Assessments - From a Cheat Sheet to a Deep Dive ]

JWTs power modern authentication, but missteps are common. In TrustedSec blog, Aaron James shares a practical guide to assessing JSON Web Tokens, highlighting common weaknesses, testing techniques, and tools every security practitioner should know. Read it now!

https://trustedsec.com/blog/keys-to-jwt-assessments-from-a-cheat-sheet-to-a-deep-dive
  • 👍 1
Post #7 2.9K
#network #nmap #nse

[ Nmap Scripting Engine (NSE) - useful scripts collection ]

The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features. It allows users to write (and share) simple scripts (using the Lua programming language ) to automate a wide variety of networking tasks.

We collected some of useful (and mostly unknown or not popular) scripts in one post (that will be regularly updated).

- nfs-ls -> get useful information about files from NFS exports
- ipidseq -> finding zombie hosts that can later be passed in to -sI
- broadcast-listener -> sniffs the network for incoming broadcast communication and attempts to decode the received packets
- grab_beacon_config -> simple PoC script to scan and acquire CobaltStrike Beacon configurations
- http-security-headers -> checks for the HTTP response headers related to security given in OWASP Secure Headers Project
- http-ntlm-info -> enumerates information from remote HTTP services with NTLM authentication enabled
- winrm -> WinRM service detection
- http-enum -> enumerates directories used by popular web applications and servers

Subscribe to see more: t.me/gravity_rainbow
Post #6 83
#education #course

[ Red Team Leaders courses and certifications ]

Catalog of multiple Offensive Security courses which includes but not limited to:
- AV/EDR
- Coding
- Active Directory
- Source Code Review
- Web Hacking
- Bug Bounty

https://courses.redteamleaders.com/catalog

Most of them are free or "Pay what you can" model.

(this is not a paid promotion, just something we saw and decided to share with you)
Post #5 67
#web #js

[ Testing JavaScript files for bug bounty hunters ]

🔁 It's safe to claim that JavaScript file enumeration is and will always play a crucial role in bug bounty!

In this comprehensive article, Intigrity cover how to find hidden API endpoints, hard-coded credentials, and DOM-based vulnerabilities buried in JavaScript files. They also include recommended tools and techniques to help you discover more issues! 🤠

Read the article now! 👇

https://www.intigriti.com/researchers/blog/hacking-tools/testing-javascript-files-for-bug-bounty-hunters
Post #4 56
#web #burp #tool #tricks

[ Burp 101 ]

Let's start our journey by introducing some of Burp Suite tips and tricks. Most people are smart but this info still can be valuable for others.

1) Need to send requests only to related domain?
(^|^[^:]+:\/\/|[^\.]+\.)domain.*


2) Need to use HTTP/2 protocol?
Burp → Settings → Network → HTTP

(you can also change it in Inspector for specific request)

3) Need to add custom header?
Settings → Sessions → Session Handling Rules -> Add -> Set a specific header value (pentest/bug-bounty) -> Scope -> set on Proxy -> URL Scope.


4) Need to see hidden UI?
Edit match/replace rules -> Response body -> Match: hidden -> Replace: himmen


5) Need to scan specific value?
Intruder -> select value -> add insertion point -> right click -> Scan selected insertion point


Subscribe to see more: t.me/gravity_rainbow
Post #3 52
Welcome.

This is our first post. Someday it will be edited to include more detailed information but for now everything you need to know is: we will actively post everything related to Cybersecurity. News, tools, attack & defense, jobs (EU/UA/PL mostly) and so on.

Our idea is simple: no bullshit, no fluff, no AI. We want to provide value for you and we will do our best to do so.

Contact @tslothrop for any questions.

Now... Let's PWN!
Post #1
Channel created

About this channel

How can I read @gravity_rainbow without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Gravity's Rainbow: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Gravity's Rainbow have?
Gravity's Rainbow (@gravity_rainbow) has 34 subscribers on Telegram, refreshed roughly every 30 minutes.
Does Gravity's Rainbow know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →