fa
Feedback
CFS - CRYPT FILE SERVICE x DSAS by INJECT [Labs]

CFS - CRYPT FILE SERVICE x DSAS by INJECT [Labs]

رفتن به کانال در Telegram

🚩 Channel was restricted by Telegram

نمایش بیشتر
اطلاعاتی وجود ندارد
مشترکین
-524 ساعت
+47 روز
+6530 روز
آرشیو پست ها
👋 Hello friends, and I would like to inform you that there is not much time left to apply for training. 🖥On the 14th, we will start and dive into the new, streamlined "Kill AV/EDR2" methods. The training will last 3 days, from Friday to Sunday inclusive. I also want to inform you that our guest from the very famous "let's not say his name yet" Red Team will take part in the training and will tell us about his methods of evading detection. So, keep up. Have a good and productive week, everyone.

AMSI Bypass ▪️It's a small debugger that creates new powershell.exe or attach to existing powershell and sets hardware breakpoint at AmsiScanBuffer() address. ▪️We then change the 3rd parameter which is length stored in R8 register to 1 ▪️This makes AmsiScanBuffer() to scan only 1 byte of buffer (our commands) which will obviously results in AMSI_RESULT_CLEAN

CrimsonEDR : Simulate the behavior of AV/EDR for malware development training https://github.com/Helixo32/CrimsonEDR?tab=readme-ov-file

🛠 A completely redesigned engine and API for its polymorphic encryption on PowerShell. In this update, we have focused on im
🛠 A completely redesigned engine and API for its polymorphic encryption on PowerShell. In this update, we have focused on improving performance and security, allowing for more efficient query processing and data protection. In the process, we have implemented new encryption algorithms that make reverse shell generation more reliable and resistant to detection. In addition, the updated API interface simplifies integration with other systems and improves user interaction. ☠️ The tests conducted on various AV and EDR systems, such as CrowdStrike, Elastic, Sentinel One, Sophos, Symantec, Bitdefender XDR and others, have demonstrated impressive results. The updated generator was able to successfully bypass detection mechanisms, which confirms its high efficiency and reliability in real conditions. 💩 injectexp.dev

Obfuscate is a PowerShell script that obfuscates a given PowerShell script file by renaming functions and variables, removing comments and unnecessary whitespace, and optionally inserting junk code. It also provides deeper levels of obfuscation, including numeric obfuscation, compression, and encryption.

🖥 PPL Exploit PoC : C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveragi
🖥 PPL Exploit PoC : C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection : https://github.com/T3nb3w/ComDotNetExploit

Dropper on COM, without using winhttp.dll wininet.dll, has a minimum of detections in runtime.

Dropper on COM, without using winhttp.dll wininet.dll, has a minimum of detections in runtime.

[Loader / Dropper] BYPASS SMARTSCREEN AND WD Prices: ZIP 140💵 / week EV + ZIP 200💵/ week MSI 150💵/ week Disabling windows defender runtime protect + add exclusion. Silent execution. Your [Malware] code signing bypass: AV / Smartscreen / Chrome alert - 500💵 1st file, - 400💵 2nd file, AV + Smartscreen - 300💵 each sign Our [Loader / Dropper] Rent week loader 700💵 Now the price for a weekly plan is 2000💵 EV Certificate included in the price!✅

EV by GlobalSign - 1800💵 (in stock, exp. in 1 year)

🖥 Start March 14 ➡️ https://injectexp.dev/t/KillAVEDR Registration is currently working in manual mode. Send a request to ou
+2
🖥 Start March 14 ➡️ https://injectexp.dev/t/KillAVEDR Registration is currently working in manual mode. Send a request to our email address injectexpdev@proton.me / where it is necessary to specify your email address for registration / choose a training plan and your telegram or TOX contact details. injectexp.dev Kill AV / EDR - Registration Training DSAS

All methods scripts / software updated from 25/02/2025. Added a new module Module 1⃣ : Introduction to EDR Evasion ➡️ Introdu
All methods scripts / software updated from 25/02/2025. Added a new module Module 1⃣ : Introduction to EDR Evasion ➡️ Introduction to EDR Evasion ➡️ Overview of Endpoint Detection and Response (EDR) solutions ➡️ Understanding EDR detection mechanisms ➡️ Introduction to EDR evasion techniques ➡️ Hands-on exercise: Understanding EDR detection mechanisms Module 2⃣ : Scripting for EDR Evasion ➡️ Scripting for EDR Evasion ➡️ Writing scripts to evade EDR detection: techniques and best practices ➡️ Hands-on exercises: Writing and testing EDR evasion scripts Module 3⃣ : BYOVD (Bring Your Own Vulnerable Driver) Method ➡️ Understanding the BYOVD method for bypassing EDR solutions ➡️ Identifying and exploiting vulnerabilities in legitimate drivers ➡️ Scripting for BYOVD: automating the process of loading vulnerable drivers and exploiting vulnerabilities ➡️ Hands-on exercise: Implementing the BYOVD method Module 4⃣ : Code Obfuscation and Anti-Debugging Techniques ➡️ Understanding code obfuscation techniques: using encoding, encryption, etc Implementing code obfuscation in scripts: using PowerShell, Python, and Bash ➡️ Understanding anti-debugging techniques: using timing, memory, and more ➡️ Implementing anti-debugging techniques in scripts: using PowerShell, Python, and Bash ➡️ Hands-on exercise: Writing an obfuscated script with anti-debugging techniques Module 5⃣ : Living Off the Land (LOTL) Techniques ➡️ Understanding LOTL techniques: using existing system tools and binaries ➡️ Implementing LOTL techniques in scripts: using PowerShell, Python, and Bash ➡️ Hands-on exercise: Writing a LOTL script to evade EDR detection Module 6⃣ : Implementing AV / EDR Evasion Scripts ➡️ Understanding how to write scripts for evasion: using techniques and best practices ➡️ Implementing evasion scripts in real-world scenarios: using PowerShell, Python, and Bash ➡️ Hands-on exercise: Writing an evasion script for a real-world scenario Module 7⃣ : Testing and Refining Evasion Scripts ➡️ Understanding how to test and refine evasion scripts: using testing frameworks and etc ➡️ Implementing testing and refinement techniques: using PowerShell, Python, and Bash ➡️ Hands-on exercise: Testing and refining an evasion script Module 8⃣ : Advanced EDR Evasion Techniques ➡️ Understanding advanced EDR evasion techniques: using fileless malware, memory-only malware, and etc ➡️ Implementing advanced EDR evasion techniques in scripts: using PowerShell, Python, and Bash ➡️ Hands-on exercise: Writing an advanced EDR evasion script Module 9⃣ : EDR Evasion in Real-World Scenarios ➡️ Understanding how to implement EDR evasion techniques in real-world scenarios ➡️ EDR evasion in various industries and environments ➡️Hands-on exercise: Implementing EDR evasion in a real-world scenario Module 1⃣0⃣ : "Silent but Deadly: Bypassing and Disabling ➡️ Review of EDR evasion techniques and best practices ➡️Understanding the importance of continuous learning and improvement in EDR evasion ➡️ AV/EDR Solutions for Stealthy Operations and Advanced Threat Simulation"

Topics : lets discuss the topics which we going to deep dive today. First topic we are going to cover is ▪️Process Injection
Topics : lets discuss the topics which we going to deep dive today. First topic we are going to cover is ▪️Process Injection - Shellcode. ▪️Enumerating process via enum ▪️Thread Hijacking and local thread creation 🖥Process Injection - Shellcode: in general and most simple words we can say the process injections is an way to inject your malicious code (we can say payload) into the process of another thing. this is also an most common way but in the below you will see more advance poc (proof of concept) we will utilize them together to bypass security. https://telegra.ph/Antivirus-Evasion-3-03-03

NOTE: WE WILL USE UUID OBFUSCATION WHICH DISCUESS IN PART 1 Local Payload Execution: Now in this topic we will cover deepdive
NOTE: WE WILL USE UUID OBFUSCATION WHICH DISCUESS IN PART 1 Local Payload Execution: Now in this topic we will cover deepdive understanding of dynamic link libraries Also know as (DLL) if i elaborate more we can say we will cover how to load malicious dll in current process . Creating dll is very simple and will be done from vs as well any version like 2019,2022 which ever you batter first of all download vs and open them add set programmic language into c++ and then select dynamic link library . this will give an basic code for an dll we will completely change them but as a beginner we understanding about dll how it work how to execute https://telegra.ph/Antivirus-Evasion-2-03-02

⚙️It’s hard to write what we cover but a roughly idea what we are going to cover in whole articles are basic coding requireme
⚙️It’s hard to write what we cover but a roughly idea what we are going to cover in whole articles are basic coding requirements, fundamental of scanning detection system how they work ➡️study about dll , ➡️basic encryptions , ➡️like xor , ➡️rc4 , ➡️payload obfuscation ipv4 ipv6 , ➡️mac fuscation , ➡️uuid fuscation, ➡️payload injection , ➡️malware binary signing , ➡️different ways of thread hijacking , (local ➡️thread creating , ➡️remote thread creation) apc injection ) - this was the syllabous for basic fundamentals for intermediate syllabous i will update on other post https://telegra.ph/Antivirus-Evasion-02-27

BRC4 Retrace v2.1.2 - 4500💵

The site will be restored within 1.5-2 hours. Technical work is underway.

Available Self-Written Cobalt Strike Artifacts. - x86/64, - .exe/dll, - Custom syscall gate, asm stabs, - Inject. When used correctly - FUD for more than six months without cleaning.

🛠 PsExeSVC - Remote Execution via Python PsExeSVC is a Python-based tool that interacts with the PsExec service to execute r
🛠 PsExeSVC - Remote Execution via Python PsExeSVC is a Python-based tool that interacts with the PsExec service to execute remote commands without relying on Windows binaries. It enables privilege escalation, remote shell access, and user authentication via primary tokens, mimicking legitimate PsExec.exe behavior while bypassing security controls like EDR detection. 🔗 Research: https://sensepost.com/blog/2025/psexecing-the-right-way-and-why-zero-trust-is-mandatory/ 🔗 Source: https://github.com/sensepost/susinternals