fa
Feedback
ZeroDayOps

ZeroDayOps

رفتن به کانال در Telegram

🚩 Channel was restricted by Telegram

نمایش بیشتر
اطلاعاتی وجود ندارد
مشترکین
-424 ساعت
-117 روز
-930 روز
آرشیو پست ها
Bypassing Detections with Command-Line Obfuscation Defensive tools like AVs and EDRs rely on command-line arguments for detec
Bypassing Detections with Command-Line Obfuscation Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executables’ parsing “flaws”, can bypass such detections. It also introduces ArgFuscator, a new tool that documents obfuscation opportunities and generates obfuscated command lines.

Bypassing Windows Defender Application Control with Loki C2 Windows Defender Application Control (WDAC) is a security solutio
Bypassing Windows Defender Application Control with Loki C2 Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.

Persistence via App Registration in Entra ID https://cyberdom.blog/persistence-via-app-registration-in-entra-id/

Releasing WebcamBOF📸 Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or scr
Releasing WebcamBOF📸 Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or screenshot). USB webcams supported (at least mine is)

Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote co
Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses. If an attacker injects an unsanitized dictionary into a DAPI request or response, they can craft an unhandled exception, allowing arbitrary Python code execution. https://github.com/0xjessie21/CVE-2025-24016

StringReaper CobaltStrike BOF designed to carve strings out of remote process memory. This tool allows operators to carve ASC
StringReaper CobaltStrike BOF designed to carve strings out of remote process memory. This tool allows operators to carve ASCII and UTF-16 strings from targeted processes, making it effective for retrieving JWT tokens, credentials, and other sensitive data directly from memory. Over the past 3 years i've had great success in using this tool on engagements. Saves time when oping from a C2 where you don't want to have to wait on a full process dump or deal with download size issues.

CVE-2025-21298: A Critical Windows OLE Zero-Click Vulnerability https://www.offsec.com/blog/cve-2025-21298
+2
CVE-2025-21298: A Critical Windows OLE Zero-Click Vulnerability https://www.offsec.com/blog/cve-2025-21298

CVE-2025-21293 Exploit (Active Directory Domain Services) WTF POC exploit
CVE-2025-21293 Exploit (Active Directory Domain Services) WTF POC exploit

Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx A few years ago, Jame
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx A few years ago, James Forshaw discovered a technique allowing to perform Kerberos relaying over HTTP by abusing local name resolution poisoning. In this article, we present the attack and propose a concrete implementation through the Responder and krbrelayx tools.

Repost from APT
💻 Elevation of Privilege via Network Configuration Operators (CVE-2025-21293) This article discusses a vulnerability in Acti
💻 Elevation of Privilege via Network Configuration Operators (CVE-2025-21293) This article discusses a vulnerability in Active Directory (CVE-2025-21293) related to the Network Configuration Operators group, which has excessive permissions to create subkeys in the registry for DnsCache and NetBT. This allows attackers to leverage Performance Counters to execute code with NT\SYSTEM privileges, potentially leading to privilege escalation. 🔗 Source: https://birkep.github.io/posts/Windows-LPE/ #ad #network #group #lpe #cve

ReverseShell_2025_01.ps1 New PowerShell reverse shell, currently undetected by AV systems (Usually valid for 1–2 weeks before
ReverseShell_2025_01.ps1 New PowerShell reverse shell, currently undetected by AV systems (Usually valid for 1–2 weeks before detection). Bonus: AI defenses bypassed with a single additional line

Go Defender Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM De
Go Defender Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

AdaptixC2 An extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix serve
AdaptixC2 An extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and the GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS operating systems. Features:
• Server/Client Architecture for Multiplayer Support • Cross-platform GUI client • Fully encrypted communications • Listener and Agents as Plugin (Extender) • Client extensibility for adding new tools • Task and Jobs storage • Files and Process browsers
Documentation

Azure Attack Paths In this blog article I want to shed some light on known attack paths in an Azure environment. The attacks
Azure Attack Paths In this blog article I want to shed some light on known attack paths in an Azure environment. The attacks are not new to many, and I relied on public research from other IT security professionals while writing this article.

Repost from Offensive Xwitter
😈 [ MrAle98 @MrAle_98 ] Finally finished to develop an exploit for CVE-2024-49138: vulnerability in CLFS.sys. I'll provide a detailed analysis in a blog post. 🔗 https://github.com/MrAle98/CVE-2024-49138-POC 🐥 [ tweet ]

emp3r0r A post-exploitation framework for Linux/Windows emp3r0r C2 (Linux/Windows) is ready for testing. Please report bugs i
emp3r0r A post-exploitation framework for Linux/Windows emp3r0r C2 (Linux/Windows) is ready for testing. Please report bugs if you find any. Read wiki to get started Download from here Write modules for emp3r0r with your favorite languages Windows support is ready with fully-interactive shell

Hey everyone, Can someone tell me why I am no longer recommended in the similar channel? @zerolmk
Hey everyone, Can someone tell me why I am no longer recommended in the similar channel? @zerolmk

RustPotato A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.

PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detectio
PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.