John Hammond
johnhammond.bsky.social
John Hammond
@johnhammond.bsky.social
Hacker. Friend. Cybersecurity Researcher at Huntress.
February got here fast-- and the 2026 Snyk Fetch the Flag CTF came up quick too! This year my friend NahamSec is hosting the game, starting NEXT THURSDAY 2/12 at 12pm ET! Free 24-hour Capture the Flag event with AR glasses as prizes ๐Ÿ˜Ž See ya there! jh.live/snyk-ftf2026
February 6, 2026 at 3:02 PM
Also, meme thumbnail experiment continues. Disaster girl feels appropriate when AI might burn down your codebase.

This is the first time Zack and I got to hang out and chat, please show him and his writeup some love! All credit to him and his work -- his blog: zkorman.com/posts/cyberd...
Cyber & Dev #2: MCP
This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series Iโ€™m doing to help give peopleโ€ฆ
zkorman.com
January 21, 2026 at 2:00 PM
I for one am totally guilty of just throwing caution to wind and poking at the newfangled whizbang AI world with reckless abandon -- but whatever "black box" we tout it to be, there's stuff you don't notice and forget that just you accepted the risk.
Cyber & Dev #2: MCP
This blog post is meant as supporting material to go along with a video I am making on the same topic (will provide a link when that goes live). This is part of a series Iโ€™m doing to help give peopleโ€ฆ
zkorman.com
January 21, 2026 at 2:00 PM
Are MCP servers safe and secure? Yes? No? Sometimes? Maybe? ... Zack Korman shows me some of his learnings on MCP security (or lack thereof) with his "Evil MCP" project ๐Ÿ˜ˆ YouTube link: youtu.be/_r_sLetar_o

1. data exfil of your prompts & code context
2. inserting vulnerabilities into your code
January 21, 2026 at 2:00 PM
Feels good to get something out the door again. I hope you take a look! YouTube link: youtu.be/Mw8DVcLSZIc
youtu.be
January 15, 2026 at 2:02 PM
I'm experimenting with MEMES in the THUMBNAIL and SHORT video TITLES to MITIGATE against CLICKBAIT

Also experimenting with longer social text promos for video releases to add more preview details and context. I no longer have to just feed algorithms, but now LLMs, too!
youtu.be
January 15, 2026 at 2:02 PM
No Registry writes, API calls or registry callbacks because it's just a single file placed on disk! Kinda neat.

This is my first recording after a month break for the holidays and it was _painful_ -- lots of fails and mistakes and it took many hours ๐Ÿ˜…
youtu.be
January 15, 2026 at 2:02 PM
3. exporting, downloading, and hijacking an existing target user profile NTUSER.DAT or HKCU Registry hive,
4. converting hives from .reg plaintext to binary with the HiveSwarming.exe tool,
5. and establishing persistence with the new backdoored NTUSER dot MAN profile we upload!
youtu.be
January 15, 2026 at 2:02 PM
Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thing๐Ÿ‘€ Hat tip to DeceptIQ et al.... we showcase:

1. breaking a Windows login with an empty user profile,
2. getting initial access EZPZ with a Sliver C2 implant,
January 15, 2026 at 2:02 PM
"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID ๐Ÿ‘€ I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak
December 13, 2025 at 2:00 PM
Infostealer malware logs -- maybe an unconventional threat intel source, but Estelle Ruellan shows me her sweet research using LLMs to analyze stealer logs at scale:
- How did a victim get infected?
- Can we uncover a threat actor when they infect themselves? and more.
Video: youtu.be/3j4jzCU0Kwc
December 12, 2025 at 4:05 PM
Continuing THE FUTURE IS ****** comic book Capture The Flag challenges! Carving email attachments to uncover malicious Microsoft Office macros with olevba, prompt injection within an AI chatbot, and tracking network packets to uncover flags! Video: youtu.be/Oiv3TaIR9UY
December 8, 2025 at 2:01 PM
Yapping about the GlassWorm supply chain malware campaign and the neato tricks it uses with "Invisible Unicode" characters -- essentially whitespace steganography, showcasing the Hangul Filler, zero-width space, & Private Use Area characters ๐Ÿคฏ Video: youtu.be/0XumkGQFEEk
December 5, 2025 at 2:00 PM
Big thanks to @tryhackme for their continued support of the channel! You can jump into the Advent of Cyber 2025 event right now, it is free to play and anyone can join to level up their cybersecurity skills with a new task every day! jh.live/aoc2025
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
jh.live
December 2, 2025 at 3:55 PM
Flattered to help start the party for the Advent of Cyber Day 02 task from TryHackMe -- walking through today's challenge using the Social Engineer Toolkit to send a phishing email and snag passwords with a simple Python HTTP server! Video: youtu.be/w8O8FcRgDXU
December 2, 2025 at 3:55 PM
Full length reverse engineering with Invoke RE! Showcasing new iterations of the "Scavenger" malware, or what we saw as "ExoTickler" previously as a fake City Skylines 2 video game mod, now w/ more crypto/creds stealing and C2. Binary Ninja, x64dbg & more: youtu.be/wFBdeak0t70
November 29, 2025 at 2:27 PM
Walking through the Advent of Cyber "Prep Track" from TryHackMe! Some warmup tasks before the real free event kicks off December 1 running through December 24 -- we start the party with password security, insecure defaults, log analysis and more. Video:
youtu.be/Ap5tIJtt4Tk
November 28, 2025 at 2:00 PM
Walking through a PowerShell keylogger, which uses some inline C# to snag Win32 API functions from user32.dll, and funnels back keys and system info to a Tor onion address -- a nifty little challenge from LetsDefend (now part of Hack The Box ๐Ÿ”ฅ) Video: youtu.be/bF72IEGzniU
November 25, 2025 at 3:32 PM
Tracking down a rogue Windows service for webshell persistence -- just a teeny weeny PowerShell HTTP server wrapped with NSSM, showcased with Wazuh and their sweet new 4.14 release with visibility on IT hygiene ๐Ÿ˜Ž Video: youtu.be/7Gn1GY5CIxg
November 24, 2025 at 5:11 PM
Hacking Twitch Chat ๐Ÿ˜Ž L3TH4L_P4ND4 shows me what looks like template injection or unsanitized variable expansion with StreamElements, then leverages Nightbot to mod yourself, ban accounts, change livestream settings or many more hijinks ๐Ÿ˜œ Video: youtu.be/8G45lYCZzZ8
November 23, 2025 at 2:01 PM
Uncovered screen recordings from threat actors! ๐Ÿ‘€ Real footage of cybercriminals using anti-detect browsers and infostealer malware logs for session hijacking, and another using GraphSpy to read their Entra ID victim's emails in Outlook! ๐Ÿ’€ Video: youtu.be/vX7JcpRqbEk
November 22, 2025 at 2:00 PM
Hat tip, kudos, and all credit where credit is due to @ PyroTek3 for his research and work referenced in this video! adsecurity.org?p=4825
Improve Entra ID Security More Quickly
At BSides Northern Virginia (BSides NoVa) in October 2025, I presented a talk on how to improve Entra ID security quickly. This post captures the key information from my talk slides. This articleโ€ฆ
adsecurity.org
November 18, 2025 at 3:00 PM
Walking through the start of Sean Metcalf's presentation and writeup on "Improving Entra ID Security More Quickly"... starting with removing some insecure defaults for user settings, device settings, and guest access! youtu.be/WUHzpDdauAw
November 18, 2025 at 3:00 PM
Solving some of the beginning Capture the Flag challenges that are included within THE FUTURE IS ****** comics... classic ciphers, mixing image R G B color values, and some quick Python code analysis! Video: youtu.be/lk9_h5DoDMw
November 16, 2025 at 2:00 PM
Playing with and poking at the recent Atomic Red Team MCP server to connect it to Claude! Sample execution of threat actor TTPs from ye ol' MITRE ATT&CK framework, in a virtual environment for a cheesy clickbait video title "haha claude hacked me lol" ๐Ÿ˜œ youtu.be/cFdOvrwxAwQ
November 14, 2025 at 2:00 PM