w0rk3r's Windows Hacking Library
رفتن به کانال در Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
نمایش بیشترکشور مشخص نشده استفناوری و برنامهها42 664
1 663
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
اطلاعاتی وجود ندارد30 روز
آرشیو پست ها
Pwning Windows Event Logging with YARA rules
https://blog.dylan.codes/pwning-windows-event-logging
@WindowsHackingLibrary
Death from Above: Lateral Movement from Azure to On-Prem AD
https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d
@WindowsHackingLibrary
FireWalker: A New Approach to Generically Bypass User-Space EDR Hooking
https://www.mdsec.co.uk/2020/08/firewalker-a-new-approach-to-generically-bypass-user-space-edr-hooking
@WindowsHackingLibrary
Death from Above: Lateral Movement from Azure to On-Prem AD
https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d
@WindowsHackingLibrary
CVE-2020-1337 – PrintDemon is dead, long live PrintDemon!
https://voidsec.com/cve-2020-1337-printdemon-is-dead-long-live-printdemon
@WindowsHackingLibrary
Attacking MS Exchange Web Interfaces
https://swarm.ptsecurity.com/attacking-ms-exchange-web-interfaces
@WindowsHackingLibrary
Telemetry Sourcerer can enumerate and disable common sources of telemetry used by AV/EDR on Windows.
https://github.com/jthuraisamy/TelemetrySourcerer
@WindowsHackingLibrary
Extending the Exploration and Analysis of Windows RPC Methods Calling other Functions with Ghidra, Jupyter Notebooks and Graphframes
https://medium.com/threat-hunters-forge/extending-the-exploration-and-analysis-of-windows-rpc-methods-calling-other-functions-with-ghidra-e4cdaa9555bd
@WindowsHackingLibrary
Bypassing LSA Protection (aka Protected Process Light) without Mimikatz on Windows 10
https://www.redcursor.com.au/blog/bypassing-lsa-protection-aka-protected-process-light-without-mimikatz-on-windows-10
@WindowsHackingLibrary
SIGRed – Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers
https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers
@WindowsHackingLibrary
A Guide to Reversing and Evading EDRs
Part 1: Introduction
http://jackson-t.ca/edr-reversing-evading-01.html
Part 2: Sensor Reconnaissance
http://jackson-t.ca/edr-reversing-evading-02.html
Part 3: Diverting EDR Telemetry to Private Infrastructure
http://jackson-t.ca/edr-reversing-evading-03.html
@WindowsHackingLibrary
Automating DLL Hijack Discovery
https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0
@WindowsHackingLibrary
Persistence: “the continued or prolonged existence of something” Series
Part 1 – Microsoft Office
https://www.mdsec.co.uk/2019/05/persistence-the-continued-or-prolonged-existence-of-something-part-1-microsoft-office
Part 2 – COM Hijacking
https://www.mdsec.co.uk/2019/05/persistence-the-continued-or-prolonged-existence-of-something-part-2-com-hijacking
Part 3 – WMI Event Subscription
https://www.mdsec.co.uk/2019/05/persistence-the-continued-or-prolonged-existence-of-something-part-3-wmi-event-subscription
@WindowsHackingLibrary
Engineering antivirus evasion
https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion
@WindowsHackingLibrary
Sysmon Image File Name Evasion
https://undev.ninja/sysmon-image-file-name-evasion
@WindowsHackingLibrary
"Heresy's Gate": Kernel Zw*/NTDLL Scraping +
"Work Out": Ring 0 to Ring 3 via Worker Factories
https://zerosum0x0.blogspot.com/2020/06/heresys-gate-kernel-zwntdll-scraping.html
@WindowsHackingLibrary
PE Parsing and Defeating AV/EDR API Hooks in C++
https://www.solomonsklash.io/pe-parsing-defeating-hooking.html
@WindowsHackingLibrary
Group Policies Going Rogue
GPSVC exposes all domain-joined Windows machines to an escalation of privileges (EoP) vulnerability.
https://www.cyberark.com/resources/threat-research-blog/group-policies-going-rogue
@WindowsHackingLibrary
Abusing Windows Telemetry for Persistence
https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence
@WindowsHackingLibrary
NINA: x64 Process Injection: (No Injection, No Allocation x64 Process Injection Technique.)
https://undev.ninja/nina-x64-process-injection
@WindowsHackingLibrary
