w0rk3r's Windows Hacking Library
رفتن به کانال در Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
نمایش بیشترکشور مشخص نشده استفناوری و برنامهها42 664
1 663
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
اطلاعاتی وجود ندارد30 روز
آرشیو پست ها
Evading Sysmon DNS Monitoring
https://blog.xpnsec.com/evading-sysmon-dns-monitoring
@WindowsHackingLibrary
Hijacking Administrative Templates
https://sdmsoftware.com/group-policy-blog/security-related/hijacking-administrative-templates
@WindowsHackingLibrary
Modern Red Team Infrastructure
https://silentbreaksecurity.com/modern-red-team-infrastructure
@WindowsHackingLibrary
Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin
https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin
@WindowsHackingLibrary
Analyzing ARP to Discover & Exploit Stale Network Address Configurations
https://www.blackhillsinfosec.com/analyzing-arp-to-discover-exploit-stale-network-address-configurations
@WindowsHackingLibrary
Bypassing CrowdStrike in an enterprise production network [in 3 different ways]
https://www.komodosec.com/post/bypassing-crowdstrike
@WindowsHackingLibrary
Heap Overflow Exploitation on Windows 10 Explained
https://blog.rapid7.com/2019/06/12/heap-overflow-exploitation-on-windows-10-explained
@WindowsHackingLibrary
Explaining the inner workings of AMSI and describing a new bypass technique
https://www.contextis.com/en/blog/amsi-bypass
@WindowsHackingLibrary
Coding a reliable CVE-2019-084 bypass
https://0x00-0x00.github.io/research/2019/05/30/Coding-a-reliable-CVE-2019-0841-Bypass.html
@WindowsHackingLibrary
Visualizing BloodHound Data with PowerBI — Part 1
https://posts.specterops.io/visualizing-bloodhound-data-with-powerbi-part-1-ba8ea4908422
@WindowsHackingLibrary
Your Session Key is My Session Key: How to Retrieve the Session Key for Any Authentication
https://blog.preempt.com/your-session-key-is-my-session-key
@WindowsHackingLibrary
Bloodhound walkthrough. A Tool for Many Tradecrafts
https://www.pentestpartners.com/security-blog/bloodhound-walkthrough-a-tool-for-many-tradecrafts
@WindowsHackingLibrary
Cylance Bypass Method
(Renaming CyMemDef64.dll to something else to dump from lsass.exe)
https://www.dru1d.ninja/2018/11/02/Cylance-Bypass
@WindowsHackingLibrary
Syncing yourself to Global Administrator in Azure Active Directory
https://blog.fox-it.com/2019/06/06/syncing-yourself-to-global-administrator-in-azure-active-directory
@WindowsHackingLibrary
How Red Teams Bypass AMSI and WLDP for .NET Dynamic Code
https://modexp.wordpress.com/2019/06/03/disable-amsi-wldp-dotnet
@WindowsHackingLibrary
Osquery for Windows access right misconfiguration Elevation of Privilege (CVE-2019-3567)
https://offsec.provadys.com/osquery-windows-acl-misconfiguration-eop.html
@WindowsHackingLibrary
SharpLocker
SharpLocker helps get current user credentials by popping a fake Windows lock screen, all output is sent to Console which works perfect for Cobalt Strike.
https://github.com/Pickfordmatt/SharpLocker
@WindowsHackingLibrary
