ru
Feedback
Source Byte

Source Byte

Открыть в Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

Больше
8 185
Подписчики
+1824 часа
+997 дней
+36030 день
Архив постов
Introduction global hook and its cases https://www.programmerall.com/article/21622234988/ hook, refers to a technique used to
Introduction global hook and its cases https://www.programmerall.com/article/21622234988/
hook, refers to a technique used to advance the use of api intercept and process windows messages. Such as a keyboard hook, the Trojans have a lot of this stuff, monitor your keyboard.
Related: [+] GoHook, Go global keyboard and mouse listener hook [+] Implementing Global Injection and Hooking in Windows #Hooking #malware_dev

An Introduction to Bypassing User Mode EDR Hooks Credit: Marcus Hutchins
Whilst this article is designed to stand on its own, if you’re interested, you can find my previous articles on these topics here, here, here and here. Surprisingly, despite all this research being over a decade old, it’s still completely relevant today. The more things change, the more they stay the same, I guess?
https://malwaretech.com/2023/12/an-introduction-to-bypassing-user-mode-edr-hooks.html #Hooking #edr #malware_dev

OffensiveNotion C2
OffensiveNotion combines the capabilities of a post-exploitation agent with the power and comfort of the Notion notetaking application. The agent sends data to and receives commands from your Notion page. Your C2 traffic blends right in as the agent receives instructions and posts results via the Notion developer API. And when your blue team looks for evidence of shenanigans, none will be the wiser.
Blog How write? YouTube --------------------------------------------------------- Related: Ox-c2 Implementing C2 and it's agent in rust Helfrix_C2 Basic C2 Server and Agent, Rust Programming Visit blog! --------------------------------------------------------- LiNk From and for our Chinese friends Rust C2框架LINK分析 link is a command and control framework written in rust https://github.com/postrequest/link
learn rust?
Enjoy! #Rust #C2 #maldev

An Introduction to Bypassing User Mode EDR Hooks Credit: Marcus Hutchins Whilst this article is designed to stand on its own, if you’re interested, you can find my previous articles on these topics here, here, here and here. Surprisingly, despite all this research being over a decade old, it’s still completely relevant today. The more things change, the more they stay the same, I guess? https://malwaretech.com/2023/12/an-introduction-to-bypassing-user-mode-edr-hooks.html

Repost from Source Byte
Explain pe file format from ARteam #pe

Техника process Injection на винде, без использования опасных функций (WriteProcessMemory, VirtualAllocEx, ...) https://undev.ninja/nina-x64-process-injection/ POC https://github.com/NtRaiseHardError/NINA

Exploit Development:
Playing ROP’em COP’em Robots with WriteProcessMemory() 77 minute read
https://connormcgarr.github.io/ROP2/ #exp

Exploit Development: Playing ROP’em COP’em Robots with WriteProcessMemory() 77 minute read #exp
Exploit Development: Playing ROP’em COP’em Robots with WriteProcessMemory() 77 minute read #exp

Step By Step Process ToMake Trojan Horse
For Your Clear Understanding I Posted This Article Sequence Wise Like What Is The Work Of This Trojan And How This Trojan Work And The Main Thing The Algorithm Of The Source Code Lets We Discuss One By One In Next Lines.
Trojan #trojan

Prometheus Prometheus software Very powerful stealer + miner + rat + keylogger + clipper GitHub #stealer #miner #rat #keylogg
Prometheus
Prometheus software Very powerful stealer + miner + rat + keylogger + clipper
GitHub #stealer #miner #rat #keylogger #clipper

windows-vs-linux-loader-architecture credit : Elliot The intentions of this document are to: - Compare the Windows, Linux, and sometimes MacOS loaders - Provide perspective on architectural and ecosystem differences as well as how they coincide with the loader - Including experiments on how flexible or rigid they are with what can safely be done during module initialization (with the loader's internal locks held) - Formally document how a modern Windows loader supports concurrency - Current open source Windows implementations, including Wine and ReactOS, perform locking similar to the legacy Windows loader (they presently don't support the "parallel loading" ability present in a modern Windows loader) - Educate, satisfy curiosity, and help fellow reverse engineers https://github.com/ElliotKillick/windows-vs-linux-loader-architecture

What is Loader Lock? credit : Elliot
In Windows, every DLL starts by executing its initialization function known as DllMain. This function runs while internal loader synchronization objects, including loader lock, are held. So, you must be especially careful not to violate a lock hierarchy in your DllMain; otherwise, a deadlock may occur.
https://elliotonsecurity.com/what-is-loader-lock/

OffensiveNotion C2 OffensiveNotion combines the capabilities of a post-exploitation agent with the power and comfort of the N
OffensiveNotion C2
OffensiveNotion combines the capabilities of a post-exploitation agent with the power and comfort of the Notion notetaking application. The agent sends data to and receives commands from your Notion page. Your C2 traffic blends right in as the agent receives instructions and posts results via the Notion developer API. And when your blue team looks for evidence of shenanigans, none will be the wiser.
Blog How write? YouTube --------------------------------------------------------- Related: Ox-c2 Implementing C2 and it's agent in rust Helfrix_C2 Basic C2 Server and Agent, Rust Programming Visit blog! --------------------------------------------------------- LiNk From and for our Chinese friends Rust C2框架LINK分析 link is a command and control framework written in rust https://github.com/postrequest/link
learn rust?
Enjoy! #Rust #C2 #maldev

REvil_full.pdf36.09 MB

sticker.webp0.20 KB

OffensiveNotion C2 OffensiveNotion combines the capabilities of a post-exploitation agent with the power and comfort of the N
OffensiveNotion C2
OffensiveNotion combines the capabilities of a post-exploitation agent with the power and comfort of the Notion notetaking application. The agent sends data to and receives commands from your Notion page. Your C2 traffic blends right in as the agent receives instructions and posts results via the Notion developer API. And when your blue team looks for evidence of shenanigans, none will be the wiser.
Blog How write? YouTube --------------------------------------------------------- Related: Ox-c2 Implementing C2 and it's agent in rust Helfrix_C2 Basic C2 Server and Agent, Rust Programming Visit blog! --------------------------------------------------------- LiNk From and for our Chinese friends Rust C2框架LINK分析 link is a command and control framework written in rust https://github.com/postrequest/link #Rust #C2 #maldev

sticker.webp0.51 KB