ch
Feedback
ZeroDayOps

ZeroDayOps

前往频道在 Telegram

🚩 Channel was restricted by Telegram

显示更多
无数据
订阅者
-424 小时
-117 天
-930 天

数据加载中...

标签云
无数据
有任何问题?请刷新页面或联系我们的客服
进出提及
---
---
---
---
---
---
吸引订阅者
四月 '25
四月 '250
在0个频道中
三月 '25
+13
在0个频道中
Get PRO
二月 '25
+16
在0个频道中
Get PRO
一月 '25
+37
在0个频道中
Get PRO
十二月 '24
+34
在0个频道中
Get PRO
十一月 '24
+66
在0个频道中
Get PRO
十月 '24
+74
在0个频道中
Get PRO
九月 '24
+45
在0个频道中
Get PRO
八月 '24
+329
在0个频道中
日期
订阅者增长
提及
频道
01 四月0
频道帖子
Bypassing Detections with Command-Line Obfuscation Defensive tools like AVs and EDRs rely on command-line arguments for detec
Bypassing Detections with Command-Line Obfuscation Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executables’ parsing “flaws”, can bypass such detections. It also introduces ArgFuscator, a new tool that documents obfuscation opportunities and generates obfuscated command lines.

2
Bypassing Windows Defender Application Control with Loki C2 Windows Defender Application Control (WDAC) is a security solutio
Bypassing Windows Defender Application Control with Loki C2 Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.
268
3
Persistence via App Registration in Entra ID https://cyberdom.blog/persistence-via-app-registration-in-entra-id/
370
4
https://cocomelonc.github.io/malware/2025/02/24/malware-tricks-45.html
424
5
Releasing WebcamBOF📸 Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or scr
Releasing WebcamBOF📸 Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or screenshot). USB webcams supported (at least mine is)
462
6
Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote co
Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses. If an attacker injects an unsanitized dictionary into a DAPI request or response, they can craft an unhandled exception, allowing arbitrary Python code execution. https://github.com/0xjessie21/CVE-2025-24016
423
7
StringReaper CobaltStrike BOF designed to carve strings out of remote process memory. This tool allows operators to carve ASC
StringReaper CobaltStrike BOF designed to carve strings out of remote process memory. This tool allows operators to carve ASCII and UTF-16 strings from targeted processes, making it effective for retrieving JWT tokens, credentials, and other sensitive data directly from memory. Over the past 3 years i've had great success in using this tool on engagements. Saves time when oping from a C2 where you don't want to have to wait on a full process dump or deal with download size issues.
408
8
CVE-2025-21298: A Critical Windows OLE Zero-Click Vulnerability https://www.offsec.com/blog/cve-2025-21298+2
CVE-2025-21298: A Critical Windows OLE Zero-Click Vulnerability https://www.offsec.com/blog/cve-2025-21298
411
9
CVE-2025-21293 Exploit (Active Directory Domain Services) WTF POC exploit
CVE-2025-21293 Exploit (Active Directory Domain Services) WTF POC exploit
305
10
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx A few years ago, Jame
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx A few years ago, James Forshaw discovered a technique allowing to perform Kerberos relaying over HTTP by abusing local name resolution poisoning. In this article, we present the attack and propose a concrete implementation through the Responder and krbrelayx tools.
294
11
💻 Elevation of Privilege via Network Configuration Operators (CVE-2025-21293) This article discusses a vulnerability in Acti
💻 Elevation of Privilege via Network Configuration Operators (CVE-2025-21293) This article discusses a vulnerability in Active Directory (CVE-2025-21293) related to the Network Configuration Operators group, which has excessive permissions to create subkeys in the registry for DnsCache and NetBT. This allows attackers to leverage Performance Counters to execute code with NT\SYSTEM privileges, potentially leading to privilege escalation. 🔗 Source: https://birkep.github.io/posts/Windows-LPE/ #ad #network #group #lpe #cve
256
12
ReverseShell_2025_01.ps1 New PowerShell reverse shell, currently undetected by AV systems (Usually valid for 1–2 weeks before
ReverseShell_2025_01.ps1 New PowerShell reverse shell, currently undetected by AV systems (Usually valid for 1–2 weeks before detection). Bonus: AI defenses bypassed with a single additional line
336
13
Go Defender Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM De
Go Defender Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.
298
14
AdaptixC2 An extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix serve
AdaptixC2 An extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and the GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS operating systems. Features: • Server/Client Architecture for Multiplayer Support • Cross-platform GUI client • Fully encrypted communications • Listener and Agents as Plugin (Extender) • Client extensibility for adding new tools • Task and Jobs storage • Files and Process browsers Documentation
823
15
Azure Attack Paths In this blog article I want to shed some light on known attack paths in an Azure environment. The attacks
Azure Attack Paths In this blog article I want to shed some light on known attack paths in an Azure environment. The attacks are not new to many, and I relied on public research from other IT security professionals while writing this article.
408
16
😈 [ MrAle98 @MrAle_98 ] Finally finished to develop an exploit for CVE-2024-49138: vulnerability in CLFS.sys. I'll provide a
😈 [ MrAle98 @MrAle_98 ] Finally finished to develop an exploit for CVE-2024-49138: vulnerability in CLFS.sys. I'll provide a detailed analysis in a blog post. 🔗 https://github.com/MrAle98/CVE-2024-49138-POC 🐥 [ tweet ]
393
17
emp3r0r A post-exploitation framework for Linux/Windows emp3r0r C2 (Linux/Windows) is ready for testing. Please report bugs i
emp3r0r A post-exploitation framework for Linux/Windows emp3r0r C2 (Linux/Windows) is ready for testing. Please report bugs if you find any. Read wiki to get started Download from here Write modules for emp3r0r with your favorite languages Windows support is ready with fully-interactive shell
535
18
Hey everyone, Can someone tell me why I am no longer recommended in the similar channel? @zerolmk
Hey everyone, Can someone tell me why I am no longer recommended in the similar channel? @zerolmk
99
19
RustPotato A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.
457
20
PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detectio
PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
411