ch
Feedback
w0rk3r's Windows Hacking Library

w0rk3r's Windows Hacking Library

前往频道在 Telegram

Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r

显示更多
未指定国家技术与应用42 664
1 663
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
No Shells Required - a Walkthrough on Using Impacket and Kerberos to Delegate Your Way to DA http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html @WindowsHackingLibrary

SysWhispers helps with AV/EDR evasion by generating header/ASM files implants can use to make direct system calls, all core syscalls are supported from Windows XP to 10. https://github.com/jthuraisamy/SysWhispers @WindowsHackingLibrary

Reversing Windows Internals (Part 1) – Digging Into Handles, Callbacks & ObjectTypes https://rayanfam.com/topics/reversing-windows-internals-part1 @WindowsHackingLibrary

Evading WinDefender ATP credential-theft: a hit after a hit-and-miss start https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass @WindowsHackingLibrary

Unrestricted Release of Offensive Security Tools Uncontrolled proliferation of Offensive Security Tools is an unnecessary contribution to real threat actor’s computer network operations. https://medium.com/@QW5kcmV3/misconceptions-unrestricted-release-of-offensive-security-tools-789299c72afe @BlueTeamLibrary

[Tool] DNCI - Dot Net Code Injector DNCI allows the injection of .Net code (.exe or .dll) remotely in unmanaged processes in windows. https://github.com/guibacellar/DNCI @WindowsHackingLibrary

[Paper] Injecting .NET Ransomware into Unmanaged Process https://exploit-db.com/docs/47680 @WindowsHackingLibrary

SharpHide Just a nice persistence trick to confuse DFIR investigation. Uses NtSetValueKey native API to create a hidden (null terminated) registry key. https://github.com/outflanknl/SharpHide @WindowsHackingLibrary