Source Byte
Открыть в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Больше8 327
Подписчики
-524 часа
-147 дней
-6330 дней
Архив постов
8 327
I created a simple Group Policy (GPO) to automatically fix CrowdStrike BSOD (Blue screen of death) issue.
Credit : Arda Büyükkaya
https://gist.github.com/whichbuffer/7830c73711589dcf9e7a5217797ca617
8 327
Global Windows outage hits computers around the world. This is linked to Crowdstrike update that cripples boot process.
Supposedly deleting “C-00000291*.sys” file in C:\Windows\System32\drivers\CrowdStrike directory fixes the issue. But editing system files you always do on your own risk :)Credit: Lukasz Olejnik #CrowdStrike
8 327
Repost from APT
🖥 Introduction for to Windows kernel exploitation
Explore the Windows Kernel with HEVD, a vulnerable driver. Dive into stack overflow exploits and bypass SMEP/KPTI protections using the sysret approach.
A detailed guide for Windows kernel explotation:
— Part 0: Where do I start?
— Part 1: Will this driver ever crash?
— Part 2: Is there a way to bypass kASLR, SMEP and KVA Shadow?
— Part 3: Can we rop our way into triggering our shellcode?
— Part 4: How do we write a shellcode to elevate privileges and gracefully return to userland?
#windows #kernel #driver #hevd #hacksys
8 327
Repost from N/a
https://engineers.inpyjama.com/learn/ldd-101
Linux device driver development free course
#Linux
#Course
#English
8 327
11 Strategies of a World-Class Cybersecurity Operations Center
by mitre
Strategy 1: Know What You Are Protecting and Why Strategy 2: Give the SOC the Authority to Do Its Job Strategy 3: Build a SOC Structure to Match Your Organizational Needs Strategy 4: Hire AND Grow Quality Staff Strategy 5: Prioritize Incident Response Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence Strategy 7: Select and Collect the Right Data Strategy 8: Leverage Tools to Support Analyst Workflow Strategy 9: Communicate Clearly, Collaborate Often, Share Generously Strategy 10: Measure Performance to Improve Performance Strategy 11: Turn up the Volume by Expanding SOC Functionality
8 327
درود. من یک مطلب کوتاهی نوشتم برای درک پروسهای که توی کرنل رخ میده موقع Null-dereference (معماری x86) و مقداری در مورد Virtual Memory Management کرنل صحبت کردم. شاید برای بچههایی که روی آسیبپذیریهای سمت کرنل کار میکنن هم جالب باشه:
https://imanseyed.github.io/posts/the-flow-of-the-kernel-upon-receiving-a-sigsegv-for-null-dereferene/
8 327
Unauthenticated SSRF on Havoc C2 teamserver via spoofed demon agent
Credit : Evan Ikeda
https://blog.chebuya.com/posts/server-side-request-forgery-on-havoc-c2/
8 327
Emulating inline decryption for triaging C++ malware
Blog
References Glory Sprout string decryptor: gsprout_string_decryption.py Glory Sprout Hash resolver: gsprout_api_resolver.py GlorySprout sample: Malwarebazaar Insight from GlorySprout and Taurus Stelaer: RussianPanda Research Blog Let’s play (again) with Predator the thief An In-Depth analysis of the new Taurus Stealer#malware_analysis
8 327
Windows Internals Learning Resources
credit : Patrick Matula
A summary of learning resources in the categories:
+ Windows Internals + Windows Debugging and Troubleshooting + Windows Performance + Windows Programminghttps://github.com/pmatula/Windows-Internals-Learning-Resources
