ch
Feedback
w0rk3r's Windows Hacking Library

w0rk3r's Windows Hacking Library

前往频道在 Telegram

Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r

显示更多
未指定国家技术与应用42 664
1 663
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
Telemetry Sourcerer can enumerate and disable common sources of telemetry used by AV/EDR on Windows. https://github.com/jthuraisamy/TelemetrySourcerer @WindowsHackingLibrary

Extending the Exploration and Analysis of Windows RPC Methods Calling other Functions with Ghidra, Jupyter Notebooks and Graphframes https://medium.com/threat-hunters-forge/extending-the-exploration-and-analysis-of-windows-rpc-methods-calling-other-functions-with-ghidra-e4cdaa9555bd @WindowsHackingLibrary

A Guide to Reversing and Evading EDRs Part 1: Introduction http://jackson-t.ca/edr-reversing-evading-01.html Part 2: Sensor Reconnaissance http://jackson-t.ca/edr-reversing-evading-02.html Part 3: Diverting EDR Telemetry to Private Infrastructure http://jackson-t.ca/edr-reversing-evading-03.html @WindowsHackingLibrary

"Heresy's Gate": Kernel Zw*/NTDLL Scraping + "Work Out": Ring 0 to Ring 3 via Worker Factories https://zerosum0x0.blogspot.com/2020/06/heresys-gate-kernel-zwntdll-scraping.html @WindowsHackingLibrary

Group Policies Going Rogue GPSVC exposes all domain-joined Windows machines to an escalation of privileges (EoP) vulnerability. https://www.cyberark.com/resources/threat-research-blog/group-policies-going-rogue @WindowsHackingLibrary

NINA: x64 Process Injection: (No Injection, No Allocation x64 Process Injection Technique.) https://undev.ninja/nina-x64-process-injection @WindowsHackingLibrary