w0rk3r's Windows Hacking Library
Open in Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Show moreThe country is not specifiedTechnologies & Applications42 664
1 663
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
No Shells Required - a Walkthrough on Using Impacket and Kerberos to Delegate Your Way to DA
http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html
@WindowsHackingLibrary
SysWhispers helps with AV/EDR evasion by generating header/ASM files implants can use to make direct system calls, all core syscalls are supported from Windows XP to 10.
https://github.com/jthuraisamy/SysWhispers
@WindowsHackingLibrary
From iPhone to NT AUTHORITY\SYSTEM
https://decoder.cloud/2019/12/12/from-iphone-to-nt-authoritysystem
@WindowsHackingLibrary
Updating adconnectdump - a journey into DPAPI
https://dirkjanm.io/updating-adconnectdump-a-journey-into-dpapi
@WindowsHackingLibrary
Reversing Windows Internals (Part 1) – Digging Into Handles, Callbacks & ObjectTypes
https://rayanfam.com/topics/reversing-windows-internals-part1
@WindowsHackingLibrary
SCshell: Fileless Lateral Movement Using Service Manager
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/scshell-fileless-lateral-movement-using-service-manager/
[Github]
https://github.com/SpiderLabs/SCShell
@WindowsHackingLibrary
Cobalt Strike 4.0 – Bring Your Own Weaponization
https://blog.cobaltstrike.com/2019/12/05/cobalt-strike-4-0-bring-your-own-weaponization
@WindowsHackingLibrary
Evading WinDefender ATP credential-theft: a hit after a hit-and-miss start
https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass
@WindowsHackingLibrary
Unrestricted Release of Offensive Security Tools
Uncontrolled proliferation of Offensive Security Tools is an unnecessary contribution to real threat actor’s computer network operations.
https://medium.com/@QW5kcmV3/misconceptions-unrestricted-release-of-offensive-security-tools-789299c72afe
@BlueTeamLibrary
[Tool] DNCI - Dot Net Code Injector
DNCI allows the injection of .Net code (.exe or .dll) remotely in unmanaged processes in windows.
https://github.com/guibacellar/DNCI
@WindowsHackingLibrary
[Paper] Injecting .NET Ransomware into Unmanaged Process
https://exploit-db.com/docs/47680
@WindowsHackingLibrary
Ghost Potato (NTLM Reflection)
https://shenaniganslabs.io/2019/11/12/Ghost-Potato.html
@WindowsHackingLibrary
RdpThief: Extracting Clear-text Credentials from Remote Desktop Clients
https://www.mdsec.co.uk/2019/11/rdpthief-extracting-clear-text-credentials-from-remote-desktop-clients
@WindowsHackingLibrary
Protecting Your Malware with blockdlls and ACG
https://blog.xpnsec.com/protecting-your-malware
@WindowsHackingLibrary
Covenant: Developing Custom C2 Communication Protocols
https://posts.specterops.io/covenant-developing-custom-c2-communication-protocols-895587e7f325
@WindowsHackingLibrary
SharpHide
Just a nice persistence trick to confuse DFIR investigation. Uses NtSetValueKey native API to create a hidden (null terminated) registry key.
https://github.com/outflanknl/SharpHide
@WindowsHackingLibrary
Exploiting RegEdit for Invisible Persistence and Binary Storage
https://github.com/ewhitehats/InvisiblePersistence/blob/master/InvisibleRegValues_Whitepaper.pdf
#Repost
@WindowsHackingLibrary
Bypass McAfee with McAfee
https://dmaasland.github.io/posts/mcafee.html
@WindowsHackingLibrary
Staying Hidden on the Endpoint: Evading Detection with Shellcode
https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html
GitHub:
https://github.com/fireeye/DueDLLigence
@WindowsHackingLibrary
