ch
Feedback
Source Byte

Source Byte

前往频道在 Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

显示更多
8 175
订阅者
+1824 小时
+997
+36030
帖子存档
با سلام و خسته نباشید خدمت همه عزیزان عذرخواهی ویژه بابت تاخیر طولانی، بخش دوم دوره SCE 450 با همون فرمون قبلی خدمت شما عزیزان 😁🌹🙏🏻

SANS SEC450-2-Black.pdf12.23 MB

https://github.com/vxCrypt0r/AMSI_VEH
A PowerShell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, function hooking or Import Address Table (IAT) modification.

APC Series: User APC Internals Credit: @0xrepnz
https://repnz.github.io/posts/apc/kernel-user-apc-api
#windows #internals #apc #note

Repost from Reverse Dungeon
Поскольку контента нет, напомню, что есть бложик с каким-то количество всяких статей ブログ.きく.コム В том числе подборка кучи всяких полезностей, связанных с ревёрсом ブログ.きく.コム/2021/10/02/Reverse-Engineering-Roadmap/ 😎❤️

Understanding ETW Patching Credit: jsecurity101 https://jsecurity101.medium.com/understanding-etw-patching-9f5af87f9d7b #internals #windows #ETW

hell yeah , my teacher MR.Amirheidari achieved rank 72 on microsoft's MSRC leaderboard i think i have more excitement than he
hell yeah , my teacher MR.Amirheidari achieved rank 72 on microsoft's MSRC leaderboard i think i have more excitement than he has 😂 https://msrc.microsoft.com/leaderboard

Mandiant report about APT1 #report

apt1_one_of_chinas_cyber_espionage_units_Pranshu_Bajpai #report

APT1 aka: Brown Fox, Byzantine Candor, COMMENT PANDA, Comment Crew, Comment Group, G0006, GIF89a, Group 3, PLA Unit 61398, Sh
APT1
aka: Brown Fox, Byzantine Candor, COMMENT PANDA, Comment Crew, Comment Group, G0006, GIF89a, Group 3, PLA Unit 61398, ShadyRAT, TG-8223
PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Army advanced persistent threat unit that has been alleged to be a source of Chinese computer hacking attacks * Download samples * #APT #APT1 #PAPER

mandiant-apt1-report.pdf6.48 MB

Repost from N/a
𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗗𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁, 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀 𝗮𝗻𝗱 𝗗𝗙𝗜𝗥 𝗦𝗲𝗿𝗶𝗲𝘀 👾 🔗 Part 1 :- https://azr43lkn1ght.github.io/Malware%20Development,%20Analysis%20and%20DFIR%20Series%20-%20Part%20I/ 🔗 Part 2 :- https://azr43lkn1ght.github.io/Malware%20Development,%20Analysis%20and%20DFIR%20Series%20-%20Part%20II/ 🔗 Part 3 :- https://azr43lkn1ght.github.io/Malware%20Development,%20Analysis%20and%20DFIR%20Series%20-%20Part%20III/ 🔗 Part 4 :- https://azr43lkn1ght.github.io/Malware%20Development,%20Analysis%20and%20DFIR%20Series%20-%20Part%20IV/ @source_chat #maldev #malware #development #analysis #dfir #digitalforensic #incidentresponse

ملیکا تو مال منی

Repost from Source Byte
[ 1 ] From a Windows driver to a fully functionnal driver. In this blogpost we'll go through the history of EDR's, how they used to work, how they work now and how we can build a fully functionnal one. Last step is a chall, bypass MyDumbEDR. https://sensepost.com/blog/2024/sensecon-23-from-windows-drivers-to-an-almost-fully-working-edr/ [ 2 ] internal mecanisms of EDR's : https://www.youtube.com/watch?v=yacpjV6kWpM&t=387s [ 3 ] MyDumbEDR ( written in C ) https://github.com/sensepost/mydumbedr ——— @islemolecule_source

Repost from N/a