Source Byte
Open in Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Show more8 206
Subscribers
+1624 hours
+1137 days
+39130 days
Posts Archive
8 202
Malware Exhibit (Malware samples in any language)
https://github.com/alvin-tosh/Malware-Exhibit
8 202
Repost from N/a
🔻𝗢𝗣𝗦𝗘𝗖 𝗙𝘂𝗻𝗱𝗮𝗺𝗲𝗻𝘁𝗮𝗹𝘀 𝗳𝗼𝗿 𝗥𝗘𝗗 𝗧𝗘𝗔𝗠𝗦 🔻
@source_chat #redteam #opsec #offensivedefense
8 202
#Red_Team_Tactics
BlackHat Europe 2022:
"Dirty Vanity: A New Approach to Code injection & EDR bypass".
8 202
Originally, a port of the Dirty Vanity project to fork and dump the LSASS process. Has been updated upon further research to attempt to duplicate open handles to LSASS.
If this fails (and it likely will), it will attempt to obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin
8 202
Abusing Windows Implementation of Fork() for Stealthy Memory Operations
https://billdemirkapi.me/abusing-windows-implementation-of-fork-for-stealthy-memory-operations/
A POC for the new injection technique, abusing windows fork API to evade EDRs.
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass-28417
https://github.com/deepinstinct/Dirty-Vanity
8 202
Multi-level Dropbox commands and TutorialRAT behind APT43
https://www-genians-co-kr.translate.goog/blog/threat_intelligence/dropbox?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wapp
8 202
A set of tools for remote password dumping.
https://github.com/Slowerzs/ThievingFox/
And the blog itself: https://blog.slowerzs.net/posts/thievingfox/
8 202
Redline Stealer: A Novel Approach
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/redline-stealer-a-novel-approach/
