w0rk3r's Windows Hacking Library
الذهاب إلى القناة على Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
إظهار المزيدلم يتم تحديد البلدالتكنولوجيات والتطبيقات42 664
1 663
المشتركون
لا توجد بيانات24 ساعات
لا توجد بيانات7 أيام
لا توجد بيانات30 أيام
أرشيف المشاركات
Module Stomping in C#
https://offensivedefence.co.uk/posts/module-stomping
@WindowsHackingLibrary
Purgalicious VBA: Macro Obfuscation With VBA Purging
https://www.fireeye.com/blog/threat-research/2020/11/purgalicious-vba-macro-obfuscation-with-vba-purging.html
@WindowsHackingLibrary
Windows RpcEptMapper Service Insecure Registry Permissions EoP
https://itm4n.github.io/windows-registry-rpceptmapper-eop
@WindowsHackingLibrary
WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques
https://www.fireeye.com/blog/threat-research/2020/11/wow64-subsystem-internals-and-hooking-techniques.html
@WindowsHackingLibrary
Using Custom Covenant Listener Profiles & Grunt Templates to Elude AV
https://offensivedefence.co.uk/posts/covenant-profiles-templates
@WindowsHackingLibrary
Using and detecting C2 printer pivoting
https://labs.f-secure.com/blog/print-c2
@WindowsHackingLibrary
Process Herpaderping:
Process Herpaderping is a method of obscuring the intentions of a process by modifying the content on disk after the image has been mapped. This results in curious behavior by security products and the OS itself.
https://jxy-s.github.io/herpaderping
@WindowsHackingLibrary
Active Directory (AD) Attacks & Enumeration at the Network Layer
https://www.lares.com/blog/active-directory-ad-attacks-enumeration-at-the-network-layer
@WindowsHackingLibrary
Introduction to Threat Intelligence ETW
A quick look into ETW capabilities against malicious API calls.
https://undev.ninja/introduction-to-threat-intelligence-etw
@BlueTeamLibrary
Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative
@WindowsHackingLibrary
Following Donut Crumbs
https://riccardoancarani.github.io/2020-10-10-donut-crumbs
@WindowsHackingLibrary
Powershell Logging: Obfuscation and some New(ish) Bypasses
Part1:
https://www.bc-security.org/post/powershell-logging-obfuscation-and-some-newish-bypasses-part-1
Part2:
https://www.bc-security.org/post/powershell-logging-obfuscation-and-some-newish-bypasses-part-2
@WindowsHackingLibrary
Evading Static Machine Learning Malware Detection Models – Part 1: The Black-Box Approach
https://blog.compass-security.com/2020/10/evading-static-machine-learning-malware-detection-models-the-black-box-approach
@WindowsHackingLibrary
Sysmon Internals - From File Delete Event to Kernel Code Execution
https://undev.ninja/sysmon-internals-from-file-delete-event-to-kernel-code-execution
@WindowsHackingLibrary
A different way of abusing Zerologon (CVE-2020-1472)
Using the Printer Bug with zerologon to relay to DSRUAPI and DCSYNC (No password reset needed)
https://dirkjanm.io/a-different-way-of-abusing-zerologon
@WindowsHackingLibrary
Abusing Group Policy Caching
https://decoder.cloud/2020/09/23/abusing-group-policy-caching
@WindowsHackingLibrary
Weaponizing Group Policy Objects (GPO) Access
https://www.trustedsec.com/blog/weaponizing-group-policy-objects-access
@WindowsHackingLibrary
Mitre's Center Releases FIN6 Adversary Emulation Plan
Blogpost: https://medium.com/mitre-engenuity/center-releases-fin6-adversary-emulation-plan-775d8c5ebe9b
Github: https://github.com/center-for-threat-informed-defense/adversary_emulation_library/tree/master/fin6
@BlueTeamLibrary
Zerologon: Unauthenticated domain controller compromise by subverting Netlogon cryptography (CVE-2020-1472)
https://www.secura.com/pathtoimg.php?id=2055
@WindowsHackingLibrary
