Source Byte
前往频道在 Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
显示更多8 320
订阅者
无数据24 小时
-157 天
-5630 天
帖子存档
8 320
"MalDev Academy Guide", 2023.
A comprehensive module-based malware development course providing fundamental to advanced level knowledge
8 320
Proof of concept code for thread pool based process injection in Windows.
Link
#malware_dev
———
@islemolecule_source
8 320
Improving the Landscape and Messaging of Offensive Tooling and Techniques
Part 1
Improving our social media conduct
Part 2
Offensive Tool and Technique Releases
credit : @mattifestation
video :
https://www.youtube.com/watch?v=u00JCQxUAY0
slides :
next post 👇🏻
#job_offers
———
@islemolecule_source
8 320
8 320
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
———
@islemolecule_source
8 320
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
———
@islemolecule_source
8 320
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
———
@islemolecule_source
8 320
Recreate undocumented structure using local types in ida pro
Link
#reverse
#malware_analysis
———
@islemolecule_source
8 320
WMI Internals series :
[ 1 ] Understanding the Basics
[ 2 ] Reversing a WMI Provider
[ 3 ] Beyond COM
8 320
Repost from vx-underground
Microsoft has announced their plan to retire WMIC. It will be replaced with an alternative in Powershell.
WMI will still be accessible with COM API
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/wmi-command-line-wmic-utility-deprecation-next-steps/ba-p/4039242
8 320
Leaks and Revelations: A Web of IRGC Networks and Cyber Companies
https://www.recordedfuture.com/leaks-and-revelations-irgc-networks-cyber-companies
8 320
KOVTER: An Evolving Malware Gone Fileless
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/kovter-an-evolving-malware-gone-fileless
8 320
What are LOLBins and How Can They be Used Maliciously?
https://www.securityhq.com/blog/security-101-lolbins-malware-exploitation/
#malware_dev , #LoLBins , #CA
———
@islemolecule_source
8 320
Living Off The Land Binaries, Scripts and Libraries
Windows binary used for handling certificates
🔗 https://lolbas-project.github.io/lolbas/Binaries/Certutil/
#malware_dev , #LoLBins
———
@islemolecule_source
8 320
Analyzing Modern Malware Techniques series
[ 1 ] Fileless Malware - A self loading technique
[ 2 ] A case of Powershell, Excel 4 Macros and VB6 (part 1 of 2)
[ 3 ] A case of Powershell, Excel 4 Macros and VB6 (part 2 of 2)
[ 4 ] I’m afraid of no packer
#old_but_gold
———
@islemolecule_source
