Source Byte
الذهاب إلى القناة على Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
إظهار المزيد8 169
المشتركون
+2524 ساعات
+887 أيام
+34530 أيام
أرشيف المشاركات
8 175
working crack for ida 9.0 arm64 mac os. Ill upload x86 mac os and linux once i wake up again. Just extract and place in your mac os applications folder
8 175
Repost from Cafe Security
ایدا نسخه 9 که تازه منتشر شده یکی زحمت کرک کردنش کشید
این واسه تولید لایسنس ایناشه
https://zerobin.org/?d5c5cf44154895e9#C9fXArBX3K7XWXWr1hSDAACtW74v5grtj12exhWUuPNP
شیوه کرکشم این دوستمون که خودش کرکش کرده نوشت:
https://x.com/alula/status/1822122939677897185
@cafe_security
8 175
Repost from dfir
سند راهنمای تشخیص تکنیک دور زدن EDR با متد LayeredSyscall
The detection guide document for the EDR evasion technique using the LayeredSyscall method.
به همراه رول های تشخیصی ELK, Sysmon, splunk 👇👇👇👇👇👇👇👇
8 175
Windows Security Internals: A Deep Dive into Windows Authentication, Authorization, and Auditing
True PDF - Final
_
8 175
Windows Process Access Token and user privilege
Privileges are listed and explained at: MSDN use the Windows Privileges to elevate your rights within the OS. Priv2Admin Understanding and Abusing Process Tokens — Part I Understanding and Abusing Process Tokens — Part II Access Tokens Abusing Tokens Adjusting Process Token PrivilegesStealing Access Tokens From Office Desktop Applications #windows #token #internals
8 175
PowerOfTcb
This directory covers how to use SeTcbPrivilege for educational purpose. SeTcbPrivilege is a multi puropse privilege. A user has SeTcbPrivilege is able to perform various token manipulation. For example, following token factors class can be manipulated with SeTcbPrivilege (but most of them cannot be manipulated for assigned primary token): Session ID Origin Mandatory Policy Integrity Level (downgrade operation does not require SeTcbPrivilege)https://github.com/daem0nc0re/PrivFu/tree/main/PowerOfTcb
8 175
https://web.archive.org/web/20240719160444/http://undocumented.ntinternals.net/
Xray(actually nudes) of windows internals
8 175
Repost from CyberSecurityTechnologies
#exploit
Techniques for Privilege Escalation on Windows
Part 1: https://www.zerodayinitiative.com/blog/2024/7/29/breaking-barriers-and-assumptions-techniques-for-privilege-escalation-on-windows-part-1
Part 2: https://www.zerodayinitiative.com/blog/2024/7/30/breaking-barriers-and-assumptions-techniques-for-privilege-escalation-on-windows-part-2
Part 3: https://www.zerodayinitiative.com/blog/2024/7/31/breaking-barriers-and-assumptions-techniques-for-privilege-escalation-on-windows-part-3
8 175
Deep Sea Phishing
[ 00 ] How to Bypass EDR With Custom Payloads
If endpoint detection and response (EDR) protections keep blocking your phishing payloads, you really should learn how to write custom payloads. If you’ve never written a custom payload, this is a great place to start. If you have some experience with custom payloads, I hope I can at least simplify the way you think about payload design to make it easy and fun.[ 01 ] Making Your Malware Look Legit to Bypasses EDR
I wanted to write this blog about several good techniques for endpoint detection and response (EDR) evasion; however, as I was writing about how to evade EDRs, I was hit with an epiphany:“EDR evasion is all about looking like legitimate software” — ph3eds, 2024
8 175
https://github.com/wikiZ/RedGuard
RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
8 175
Injecting Malicious Code into PDF Files and Creating a PDF Dropper
PDF files are often considered static documents by most people. However, the PDF standard allows for the execution of JavaScript code within the document. This feature offers various attack vectors that can be used for Red Team tests and cybersecurity research. In this article, we will examine how to inject JavaScript into a PDF file to download a file from a specific URL and establish a Command and Control (C2) connection using this method.
https://cti.monster/blog/2024/07/25/pdfdropper.html
8 175
Repost from CyberSecurity Shield
با سلام و خسته نباشید خدمت همه عزیزان
عذرخواهی ویژه بابت تاخیر طولانی،
بخش دوم دوره SCE 450 با همون فرمون قبلی خدمت شما عزیزان 😁🌹🙏🏻
