w0rk3r's Windows Hacking Library
前往频道在 Telegram
1 663
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
Understanding and Abusing Process Tokens — Part I
https://medium.com/@seemant.bisht24/understanding-and-abusing-process-tokens-part-i-ee51671f2cfa
Understanding and Abusing Access Tokens — Part II
https://medium.com/@seemant.bisht24/understanding-and-abusing-access-tokens-part-ii-b9069f432962
@WindowsHackingLibrary
Detecting and Advancing In-Memory .NET Tradecraft
https://www.mdsec.co.uk/2020/06/detecting-and-advancing-in-memory-net-tradecraft
@WindowsHackingLibrary
AppDomainManager Injection and Detection
https://pentestlaboratories.com/2020/05/26/appdomainmanager-injection-and-detection
@WindowsHackingLibrary
Using Syscalls to Inject Shellcode on Windows
https://www.solomonsklash.io/syscalls-for-shellcode-injection.html
@WindowsHackingLibrary
Chimichurri Reloaded - Giving a Second Life to a 10-year old Windows Vulnerability
https://itm4n.github.io/chimichurri-reloaded
@WindowsHackingLibrary
Invoking System Calls and Windows Debugger Engine
https://modexp.wordpress.com/2020/06/01/syscalls-disassembler/
@WindowsHackingLibrary
Process Injection Part 1 | CreateRemoteThread()
https://sevrosecurity.com/2020/04/08/process-injection-part-1-createremotethread
Process Injection Part 2 | QueueUserAPC()
https://sevrosecurity.com/2020/04/13/process-injection-part-2-queueuserapc
@WindowsHackingLibrary
Windows Server 2008R2-2019 NetMan DLL Hijacking
https://itm4n.github.io/windows-server-netman-dll-hijacking
@WindowsHackingLibrary
LDAPFragger: Command and Control over LDAP attributes
https://blog.fox-it.com/2020/03/19/ldapfragger-command-and-control-over-ldap-attributes
@WindowsHackingLibrary
Kerberosity Killed the Domain: An Offensive Kerberos Overview
https://posts.specterops.io/kerberosity-killed-the-domain-an-offensive-kerberos-overview-eb04b1402c61
@WindowsHackingLibrary
[PT-BR]
CVE-2020-0668 Windows LPE - Análise e Exploração
https://youtu.be/KiqvlIc-cxY
@WindowsHackingLibrary
Adaptive DLL Hijacking
https://silentbreaksecurity.com/adaptive-dll-hijacking
@WindowsHackingLibrary
Bypass Windows 10 User Group Policy (and more) with this One Weird Trick
https://medium.com/tenable-techblog/bypass-windows-10-user-group-policy-and-more-with-this-one-weird-trick-552d4bc5cc1b
@WindowsHackingLibrary
CVE-2020-0618: RCE in SQL Server Reporting Services (SSRS)
https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs
@WindowsHackingLibrary
Rethinking Credential Theft
https://labs.f-secure.com/blog/rethinking-credential-theft
@WindowsHackingLibrary
(Ab)using Kerberos from Linux
https://www.onsecurity.co.uk/blog/abusing-kerberos-from-linux
@WindowsHackingLibrary
Attacking Azure, Azure AD, and Introducing PowerZure
https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a
@WindowsHackingLibrary
SpecterOps' Adversary Tactics - PowerShell Training course material
https://github.com/specterops/at-ps
@WindowsHackingLibrary
Mimidrv In Depth: Exploring Mimikatz’s Kernel Driver
https://posts.specterops.io/mimidrv-in-depth-4d273d19e148
@WindowsHackingLibrary
