ch
Feedback
w0rk3r's Windows Hacking Library

w0rk3r's Windows Hacking Library

前往频道在 Telegram

Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r

显示更多
未指定国家技术与应用42 664
1 663
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
Do You Really Know About LSA Protection (RunAsPPL)? https://itm4n.github.io/lsass-runasppl @WindowsHackingLibrary

Forging malicious DOC, undetected by all VirusTotal static engines https://arielkoren.com/blog/2020/12/24/forging-malicious-doc @WindowsHackingLibrary

Gnome is a module to load your signed driver stealthily. The driver is extracted from the Gnome loader, dropped to disk and loaded using NtLoadDriver instead of the usual service creation driver loading which can be noisy and leaves large forensic artefacts behind such as service creation, service start/stop logs etc. https://github.com/slaeryan/AQUARMOURY/tree/master/Gnome @WindowsHackingLibrary