Source Byte
Open in Telegram
ŲØīÛØ§Øą ÚĐØģÛ ØĻØ§ÛØŊ ÚĐØē ØđØīŲ ØĻŲūØąŲÛØēØŊ ŲÛŲ Ø·ØĻØđ ÚĐŲ Ų Ų ØŊØ§ØąŲ ØĻا ØđŲŲ ŲÛØ§Ų ÛØēØŊ Saadi Shirazi 187
Show more7 843
Subscribers
-224 hours
+87 days
+14630 days
Posts Archive
7 841
Proof of concept code for thread pool based process injection in Windows.
Link
#malware_dev
âââ
@islemolecule_source
7 841
Improving the Landscape and Messaging of Offensive Tooling and Techniques
Part 1
Improving our social media conduct
Part 2
Offensive Tool and Technique Releases
credit : @mattifestation
video :
https://www.youtube.com/watch?v=u00JCQxUAY0
slides :
next post ððŧ
#job_offers
âââ
@islemolecule_source
7 841
7 841
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
âââ
@islemolecule_source
7 841
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
âââ
@islemolecule_source
7 841
HyperDbg v0.8 is released!
# [0.8.0.0] - 2024-01-28
New release of the HyperDbg Debugger thanks to @Mattiwatti.
# Changed
- Fix miscalculating MTRRs in 13th gen processors
# Added
- The !mode event command is added to detect kernel-to-user and user-to-kernel transitions
https://docs.hyperdbg.org/commands/extension-commands/mode
- The 'preactivate' command is added to support initializing special functionalities in the Debugger Mode
https://docs.hyperdbg.org/commands/debugging-commands/preactivate
âââ
@islemolecule_source
7 841
Recreate undocumented structure using local types in ida pro
Link
#reverse
#malware_analysis
âââ
@islemolecule_source
7 841
WMI Internals series :
[ 1 ] Understanding the Basics
[ 2 ] Reversing a WMI Provider
[ 3 ] Beyond COM
7 841
Repost from vx-underground
Microsoft has announced their plan to retire WMIC. It will be replaced with an alternative in Powershell.
WMI will still be accessible with COM API
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/wmi-command-line-wmic-utility-deprecation-next-steps/ba-p/4039242
7 841
Leaks and Revelations: A Web of IRGC Networks and Cyber Companies
https://www.recordedfuture.com/leaks-and-revelations-irgc-networks-cyber-companies
7 841
KOVTER: An Evolving Malware Gone Fileless
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/kovter-an-evolving-malware-gone-fileless
7 841
What are LOLBins and How Can They be Used Maliciously?
https://www.securityhq.com/blog/security-101-lolbins-malware-exploitation/
#malware_dev , #LoLBins , #CA
âââ
@islemolecule_source
7 841
Living Off The Land Binaries, Scripts and Libraries
Windows binary used for handling certificates
ð https://lolbas-project.github.io/lolbas/Binaries/Certutil/
#malware_dev , #LoLBins
âââ
@islemolecule_source
7 841
Analyzing Modern Malware Techniques series
[ 1 ] Fileless Malware - A self loading technique
[ 2 ] A case of Powershell, Excel 4 Macros and VB6 (part 1 of 2)
[ 3 ] A case of Powershell, Excel 4 Macros and VB6 (part 2 of 2)
[ 4 ] Iâm afraid of no packer
#old_but_gold
âââ
@islemolecule_source
Available now! Telegram Research 2025 â the year's key insights 
