w0rk3r's Windows Hacking Library
前往频道在 Telegram
1 663
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
Azure AD Connect for Red Teamers
https://blog.xpnsec.com/azuread-connect-for-redteam
@WindowsHackingLibrary
Getting PowerShell Empire Past Windows Defender
https://www.blackhillsinfosec.com/getting-powershell-empire-past-windows-defender
@WindowsHackingLibrary
Bypasses Microsoft's Anti-Malware Scan Interface for a PowerShell session process started through the "Start-Job" cmdlet, the PID of which is accessed using "Enter-PSHostProcess"
https://github.com/securemode/Bypass-AMSI9000
@WindowsHackingLibrary
External C2, IE COM Objects and how to use them for Command and Control
https://www.mdsec.co.uk/2019/02/external-c2-ie-com-objects-and-how-to-use-them-for-command-and-control
@WindowsHackingLibrary
Entering a Covenant: .NET Command and Control
https://posts.specterops.io/entering-a-covenant-net-command-and-control-e11038bcf462
@WindowsHackingLibrary
PoC: Using CloudFlare as an HTTP C2 with PowerShell Empire
https://holdmybeersecurity.com/2019/02/07/poc-using-cloudflare-as-an-http-c2-with-powershell-empire
@WindowsHackingLibrary
Round of use Winrm code execution XML
https://medium.com/@mattharr0ey/round-of-use-winrm-code-execution-xml-6e3219d3e31
@WindowsHackingLibrary
Exploiting Malwarebytes Anti-Exploit
https://acru3l.github.io/2019/02/02/exploiting-mb-anti-exploit
@WindowsHackingLibrary
XXE that can Bypass WAF Protection
https://lab.wallarm.com/xxe-that-can-bypass-waf-protection-98f679452ce0
@FromZer0toHero
[PrivExchange] From user to domain admin in less than 60sec
http://blog.randorisec.fr/privexchange-from-user-to-domain-admin-in-less-than-60sec
@WindowsHackingLibrary
How to Argue like Cobalt Strike
https://blog.xpnsec.com/how-to-argue-like-cobalt-strike
@WindowsHackingLibrary
Too much % makes Event Viewer drunk
http://www.hexacorn.com/blog/2019/01/27/too-much-makes-event-viewer-drunk
@WindowsHackingLibrary
Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory
https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html
@WindowsHackingLibrary
Bypassing Network Restrictions Through RDP Tunneling
https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
@WindowsHackingLibrary
Local Admin Access and Group Policy Don’t Mix
https://www.trustedsec.com/2019/01/local-admin-access-and-group-policy-dont-mix
@WindowsHackingLibrary
Technical White Paper: Finding and Exploiting the Check Point ZoneAlarm Anti-Virus for Local Privilege Escalation
https://www.illumant.com/blog/2019/01/16/check-point-anti-virus-technical-white-paper
@WindowsHackingLibrary
Abusing Exchange: One API call away from Domain Admin
https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin
@WindowsHackingLibrary
Abusing Office Web Add-ins (for fun and limited profit)
https://www.mdsec.co.uk/2019/01/abusing-office-web-add-ins-for-fun-and-limited-profit
@WindowsHackingLibrary
Bypass EDR’s memory protection, introduction to hooking
https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6
@WindowsHackingLibrary
