Ceri Coburn
Principal Security Consultant
In his current role at NetSPI, Ceri has been involved in developing robust internal capabilities for red team operations, enabling NetSPI to proactively identify and mitigate new security threats for their clients.
Ceri is also a passionate advocate for knowledge sharing within the cybersecurity community. He has published several open-source tools that have been widely adopted by security professionals worldwide. His blogs and articles provide valuable guidance on new red teaming techniques, vulnerabilities and tooling for use within the cybersecurity space.
Ceri regularly presents at leading security conferences, where he shares his expertise and insights on a range of topics, from vulnerability disclosure to advanced red teaming techniques.
Open-Source Projects
https://github.com/NetSPI/BOF-PE
https://github.com/CCob/BOF.NET
https://github.com/CCob/SweetPotato
https://github.com/CCob/ThreadlessInject
https://github.com/CCob/Shwmae
Connect With Me on Social
X/Twitter
My GitHub Repo
More By Ceri Coburn
BOFScale: A CDN-Fronted Tailnet from a BOF-PE
August 19, 2026
Discover how BOFScale leverages a modified Tailscale daemon compiled as a BOF-PE to seamlessly hide C2 traffic and DERP relays behind CDNs using standard WebSockets.
Pipe Dreams: Remote Code Execution via Quest Desktop Authority Named Pipe
February 1, 2026
Discover the risks of the CVE-2025-67813 vulnerability in Quest Desktop Authority. Learn how this RCE flaw impacts your organization and how to mitigate it.
CVE-2025-4660: Forescout SecureConnector RCE
July 16, 2025
Learn about the high-risk RCE vulnerability in Forescout SecureConnector allows attackers to turn security agents into C2 channels.
CVE-2025-21299 and CVE-2025-29809: Unguarding Microsoft Credential Guard
April 15, 2025
Learn more about the January 2025 Patch Tuesday that addresses a critical vulnerability where Kerberos canonicalization flaws allow attackers to bypass Virtualization Based Security and extract protected TGTs from Windows systems.
The Things We Think and Do Not Say: The Future of Our Beacon Object Files (BOFs)
March 19, 2025
Learn about a reference design for a new Beacon Object Files portable executable concept and helpful features.