fa
Feedback
Source Byte

Source Byte

رفتن به کانال در Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

نمایش بیشتر
8 185
مشترکین
+1824 ساعت
+997 روز
+36030 روز
آرشیو پست ها
post updated : part 21 added Getting started with Event Tracing for Windows in C# credit : Alex Khanin https://medium.com/@alexkhanin/getting-started-with-event-tracing-for-windows-in-c-8d866e8ab5f2

Bypassing PESieve and Moneta (The "easy" way....?) It contains several parts. Lockd: This is the main Gargoyle component sRDI-Master: This has been slightly re worked to provide a free mechanism. test.profile: This sample profile shows required options to work ShellcodeRDI.py: This is the altered python generator with the new sRDI assembly Blog GitHub #maldev

Repost from APT
🌀Voidgate A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes by performing on-the-fly decryption of individual encrypted assembly instructions, thus rendering memory scanners useless for that specific memory page. 🔗 Source https://github.com/vxCrypt0r/Voidgate #av #edr #evasion #hwbp #cpp

PE-LiteScan (or PELS) is a simple heuristic analyzer for common PE-anomalies, specifically focusing on the detection of packers and protectors. Designed for Windows and Linux. https://github.com/DosX-dev/PE-LiteScan

updated : part 19 & 20 added - New Perspectives on ETW Patching Telemetry - Malware academy : ( modules 12 - 17 )
+ Event Tracing For Windows - Introduction + Event Tracing For Windows - ETW Tools + Event Tracing For Windows - ETW Bypass Via Byte Patching + Event Tracing For Windows - Improved Patching + Event Tracing for Windows - Patchless ETW Bypass Via HBPs + Event Tracing For Windows - ETW Provider Session Hijacking

MalDev_modules_12-18_ETW series.pdf8.17 MB

guys if anyone have this maldev academy modules will be great to share them on the group so i can add and make this ETW serie
guys if anyone have this maldev academy modules will be great to share them on the group so i can add and make this ETW series more complete :)

updated : part 19 added New Perspectives on ETW Patching Telemetry

Repost from Cafe Security

Repost from Infosec Fortress
#binary #reverse #slides ——— 🆔 @Infosec_Fortress

Repost from Infosec Fortress
Cindy Xiao - Reversing Rust Binaries #binary #reverse #slides ——— 🆔 @Infosec_Fortress
Cindy Xiao - Reversing Rust Binaries #binary #reverse #slides ——— 🆔 @Infosec_Fortress

Repost from Infosec Fortress
#reverse #binary #slides ——— 🆔 @Infosec_Fortress

Repost from Infosec Fortress
Skochinsky - Recon (2011) - Practical C++ Decompilation #reverse #binary #slides ——— 🆔 @Infosec_Fortress
Skochinsky - Recon (2011) - Practical C++ Decompilation #reverse #binary #slides ——— 🆔 @Infosec_Fortress

Updated

new process injection technique called Mockingjay allows attackers to stealthily execute malicious code https://wins21.co.kr/kor/promotion/information.html?bmain=view&language=KOR&uid=4037 #injection

Windows-PE-Definitive-Guide-Chapter-01.pdf

#eBook #WindowsPE #DWORD 🏳️باز نویسی و ترجمه کتاب Windows PE权威指南 🔥 این کتاب به‌طور جامع و مفصل به تحلیل فرمت فایل PE و تکنی
#eBook #WindowsPE #DWORD 🏳️باز نویسی و ترجمه کتاب Windows PE权威指南 🔥 این کتاب به‌طور جامع و مفصل به تحلیل فرمت فایل PE و تکنیک‌های برنامه‌نویسی مرتبط با آن می‌پردازد و جنبه‌های مختلف امنیتی و مدیریت پروسس های سیستمی و مکانیسم‌های سطح پایین آن را مورد بررسی قرار می‌دهد.
با توجه به تاریخ انتشار کتاب Windows PE权威指南 که به زبان چینی و در سال 2011 به چاپ رسیده است، در بازنویسی این کتاب سعی کرده‌ام مطالب و ابزارهای قدیمی را حذف کنم و از نرم‌افزارهای به‌ روز و مطالب جدید استفاده کنم. به همین دلیل ممکن است بعضی از موضوعات به‌طور کامل تغییر یا جایگزین شوند و یا حتی بر حسب نیاز مطالب جدیدی اضافه گردند.
سطح مطالب این کتاب پیشرفته است و موضوعاتی که مطرح می‌شوند ممکن است نیاز به داشتن پیش‌نیاز باشند. به طور مثال، کدنویسی پروژه‌ها به زبان اسمبلی و در محیط برنامه‌نویسی انجام می‌شود، بنابراین شما باید زبان اسمبلی را بدانید و با محیط برنامه‌نویسی به زبان اسمبلی آشنایی داشته باشید. تمرکز این کتاب بر تشریح ساختار فایل‌های PE خواهد بود و به آموزش پیش‌نیازها یا سایر موارد اشاره نخواهیم کرد. با این حال، در هر فصل بخشی تحت عنوان منابع وجود دارد که برای درک و آشنایی بیشتر شما با بعضی مطالب، منابع مناسبی معرفی خواهند شد.
فصل اول : محیط توسعه Windows PE تعداد صفحات : 29 صفحه 💎دریافت فصل اول | گیتهاب کتاب 🦅 کانال بایت امن | گروه بایت امن _

Repost from zerodaytraining
Patch candidate for Oracle VirtualBox VirtIOCore Buffer Overflow Local Privilege Escalation Vulnerability (Pwn2Own Vancouver
Patch candidate for Oracle VirtualBox VirtIOCore Buffer Overflow Local Privilege Escalation Vulnerability (Pwn2Own Vancouver 2024 VM Escape exploit) There was an insufficient check for numbers of in/out data segment descriptors supplied by Guest OS into Virtio devices. Check added in virtioCoreR3VirtqAvailBufGet IO processing loop ensures that data sent in by the guest through virtio kernel device modules cannot exceed storage availability in hypervisor memory. Exploit by overflowing buffers in pVirtqBuf-aSegsIn/aSegsOut @thezdi @OnlyTheDuck @alisaesage