Source Byte
Ir al canal en Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Mostrar más8 129
Suscriptores
+1524 horas
+627 días
+29330 días
Archivo de publicaciones
8 129
Repost from N/a
سلام،
به دنبال فرصت همکاری در حوزه Red Teaming و Offensive Security هستم. اگر در تیم/شرکت خود به فردی با تخصصهای زیر نیاز دارید و امکان همکاری ریموت یا حضوری فراهم است، خوشحال میشم در ارتباط باشیم.
خلاصهای از مهارتها و توانمندیها: Active Directory Attacks: Kerberos attacks , Pass-the-Hash/Ticket based attacks, ACL Abuse, Lateral Movement, Privilege Escalation... Initial Access: abuse of various file types (.lnk, .wsr, .scr ....), script-based implants, custom loaders Red Team Tooling: development and execution of C2, Loaders, Shellcode, and AV/EDR bypass techniques COM Object Abuse & Reverse Engineering objects Reverse Engineering & Malware Analysis for New techniques Programming & Scripting: C/C++ (system programming, multithreading), C#, PowerShell, Python MITRE ATT&CK Framework: designing and implementing complete Red Team tactics & techniques Red Team Operations: Recon, Social Engineering, Exploitation, Persistence, Lateral Movement, Exfiltration Scenario Design: creating realistic attack scenarios for testing defenses🔹 ساکن تهران هستم و آماده همکاری حضوری یا ریموت. اگر چنین فرصتی در تیم/شرکت شما وجود دارد، لطفاً به من پیام دهید. @Ke3rNel
8 129
Repost from N/a
HyperDbg v0.16 is released! 🐞💫✨
This version adds a new event command '!xsetbv', along with bug fixes, performance improvements, and progress on the user-mode debugger in VMI mode.
Check it out:
https://github.com/HyperDbg/HyperDbg/releases/tag/v0.16
For more information, check the documentation:
https://docs.hyperdbg.org/commands/extension-commands/xsetbv
8 129
DOM-based Extension Clickjacking: Your Password Manager Data at Risk
https://marektoth.com/blog/dom-based-extension-clickjacking/
8 129
Repost from Infosec Fortress
CVE-2025-52915: A BYOVD Evolution Story
🔗 Link
#exploitation
#av
#cve
———
🆔 @Infosec_Fortress
8 129
Repost from ARVIN
بر اساس این تحقیق بر اساس فایل لاگ مربوط به کارمند نوبیتکس با سطح دسترسی بالا و سرچ هیستوری های آن مشخص شده این کارمند تعداد زیادی اپ های کرک شده را از منابعی مثل soft98 و p30download دانلود کرده بوده
8 129
Repost from ARVIN
NEW RESEARCH: How $81M vanished from Iran's largest crypto exchange
https://akatsukilegion.netlify.app/nobitex_breach-2025
8 129
An Undocumented 64-bit Keylogger Targeting Windows Systems
https://github.com/ShadowOpCode/RustMe_Keylogger/blob/main/RustMe%20Keylogger.pdf
8 129
Repost from CyberSecurity Shield
یک روز تعطیل که ۶:۳۰ بیدار میشی منجر به تولید #مقاله میشه! یک بار برای همیشه تکلیف epp و edr و xdr رو با هم معلوم کنیم
8 129
Repost from 1N73LL1G3NC3
🧩 When too much access is not enough: a story about Confluence and tokens
During a Red Team engagement, we compromised an AWS account containing a Confluence instance hosted on an EC2 virtual machine. Although we fully compromised the machine hosting the Confluence instance, we did not have valid credentials to log in but were able to interact with the underlying database. This led us to study the structure of the Confluence database and the mechanism for generating API tokens.
P.S. Еще несколько полезных ссылок со старого канала:📜 Creating a Malicious Atlassian Plugin 🔗 Malfluence A PoC for a malicious Confluence plugin, which can access all content inside a Confluence instance, access the database directly, and execute arbitrary commands on the underlying Linux server. 📜 Stealing All of the Confluence Things 🔗 Conf-Thief A Red Team tool for exfiltrating sensitive data from Confluence pages. 🔗 AtlasReaper A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances. 🔗 Jecretz Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets.
8 129
Repost from Infosec Fortress
From Chrome renderer code exec to kernel with MSG_OOB
🔗 Link
#browser
#exploitation
#kernel
#linux
———
🆔 @Infosec_Fortress
8 129
Repost from APT
🛡CreateProcessAsPPL
This is a utility for running processes with Protected Process Light (PPL) protection, enabling bypass of EDR/AV solution defensive mechanisms. It leverages legitimate Windows clipup.exe functionality from System32 to create protected processes that can overwrite antivirus service executable files.
🔗 Source:
https://github.com/2x7EQ13/CreateProcessAsPPL
#av #edr #bypass #ppl
