w0rk3r's Windows Hacking Library
Открыть в Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
БольшеСтрана не указанаТехнологии и приложения42 664
1 663
Подписчики
Нет данных24 часа
Нет данных7 дней
Нет данных30 дней
Архив постов
Inside Microsoft's plan to kill PPLFault
"In this research publication, we'll learn about upcoming improvements to the Windows Code Integrity subsystem that will make it harder for malware to tamper with Anti-Malware processes and other important security features."
https://www.elastic.co/security-labs/inside-microsofts-plan-to-kill-pplfault
@WindowsHackingLibrary
CVE-2023-38146: Arbitrary Code Execution via Windows Themes
https://exploits.forsale/themebleed/
@WindowsHackingLibrary
Windows Secrets Extraction: A Summary
https://www.synacktiv.com/publications/windows-secrets-extraction-a-summary
@WindowsHackingLibrary
I’ve Got a Golden Twinkle in My Eye
https://www.youtube.com/watch?v=ABd0dm8MbDo
@WindowsHackingLibrary
External Trusts Are Evil // Breaking Trust Transitivity
https://exploit.ph/external-trusts-are-evil.html
@WindowsHackingLibrary
At the Edge of Tier Zero: The Curious Case of the RODC
https://posts.specterops.io/at-the-edge-of-tier-zero-the-curious-case-of-the-rodc-ef5f1799ca06
@WindowsHackingLibrary
Fantastic Rootkits: And Where to Find Them (Part 1)
https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-1
@WindowsHackingLibrary
Analysing LastPass, Part 1
https://www.mdsec.co.uk/2022/10/analysing-lastpass-part-1
@WindowsHackingLibrary
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
https://github.com/Dec0ne/KrbRelayUp
@WindowsHackingLibrary
Group Policy Folder Redirection CVE-2021-26887
https://decoder.cloud/2022/04/27/group-policy-folder-redirection-cve-2021-26887
@WindowsHackingLibrary
Introducing the Golden GMSA Attack
https://www.semperis.com/blog/golden-gmsa-attack
@WindowsHackingLibrary
Exploring Windows UAC Bypasses: Techniques and Detection Strategies
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
@BlueTeamLibrary
Sandboxing Antimalware Products for Fun and Profit
https://elastic.github.io/security-research/whitepapers/2022/02/02.sandboxing-antimalware-products-for-fun-and-profit/article
@WindowsHackingLibrary
Delegate to KRBTGT service
https://skyblue.team/posts/delegate-krbtgt
@WindowsHackingLibrary
AD CS: weaponizing the ESC7 attack
https://www.blackarrow.net/adcs-weaponizing-esc7-attack
@WindowsHackingLibrary
Windows Drivers Reverse Engineering Methodology
https://voidsec.com/windows-drivers-reverse-engineering-methodology
@WindowsHackingLibrary
Exploit samAccountName spoofing with Kerberos
https://cloudbrothers.info/en/exploit-kerberos-samaccountname-spoofing
@WindowsHackingLibrary
CVE-2021-42287/CVE-2021-42278 Weaponisation
https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
@WindowsHackingLibrary
Windows Exploitation Tricks: Relaying DCOM Authentication
https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html
@WindowsHackingLibrary
