ru
Feedback
Source Byte

Source Byte

Открыть в Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

Больше
8 328
Подписчики
-424 часа
-97 дней
-5930 дней
Архив постов
A Syscall Journey in the Windows Kernel
What's happening after a syscall
Credit: Alice https://alice.climent-pommeret.red/posts/a-syscall-journey-in-the-windows-kernel #internals #windows

Repost from KS note
⚒ How to calculate the Address of Contract using WalletAddress and WalletNonce using Foundry 🔗 Learn Foundry
+1
⚒ How to calculate the Address of Contract using WalletAddress and WalletNonce using Foundry 🔗 Learn Foundry

Fun with Ntdll address
+1
Fun with Ntdll address

sgn
SGN is a polymorphic binary encoder for offensive security purposes such as generating statically undetecable binary payloads. It uses a additive feedback loop to encode given binary instructions similar to LSFR. This project is the reimplementation of the original Shikata ga nai in golang with many improvements.
https://github.com/EgeBalci/sgn #shellcode

Ringzer0 RET2 Browser Exploitation.rar11.01 MB

BounceBack redirector for your red team operation security #c2 #infrastructure #redteam #redirector
BounceBack redirector for your red team operation security #c2 #infrastructure #redteam #redirector

Windows API Function Cheatsheets https://github.com/7etsuo/windows-api-function-cheatsheets index :
File Operations Process Management Memory Management Thread Management Dynamic-Link Library (DLL) Management Synchronization Interprocess Communication Windows Hooks Cryptography Debugging Winsock Registry Operations Error Handling Resource Management Unicode String Functions String Length String Copy String Concatenation String Comparison String Search Character Classification and Conversion Win32 Structs Cheat Sheet Common Structs Win32 Sockets Structs Cheat Sheet (winsock.h) Win32 Sockets Structs Cheat Sheet (winsock2.h) Win32 Sockets Structs Cheat Sheet (ws2def.h) Code Injection Techniques 1. DLL Injection 2. PE Injection 3. Reflective Injection 4. APC Injection 5. Process Hollowing (Process Replacement) 6. AtomBombing 7. Process Doppelgänging 8. Process Herpaderping 9. Hooking Injection 10. Extra Windows Memory Injection 11. Propagate Injection 12. Heap Spray 13. Thread Execution Hijacking 14. Module Stomping 15. IAT Hooking 16. Inline Hooking 17. Debugger Injection 18. COM Hijacking 19. Phantom DLL Hollowing 20. PROPagate 21. Early Bird Injection 22. Shim-based Injection 23. Mapping Injection 24. KnownDlls Cache Poisoning Process Enumeration

Credential Dumping: NTDS.dit In this article, you will learn how passwords are stored in NTDS.dit file on Windows Server and then we will learn how to dump these credentials hashes from NTDS.dit file. Table of Content ▪ Introduction to NTDS ▪ NTDSPartitions ▪ DatabaseStorageTable ▪ ExtractingCredentialbyExploitNTDS.ditinMultipleMethods ▪ FGDump ▪ NTDSUtil ▪ DSInternals ▪ NTDSDumpEx ▪ Metasploit ▪ NTDS_location ▪ NTDS_grabber ▪ secretsdump ▪ CrackMapExec ▪ CrackingHashes

Directory Services Internals (DSInternals) PowerShell Module and Framework https://github.com/MichaelGrafnetter/DSInternals/t
Directory Services Internals (DSInternals) PowerShell Module and Framework https://github.com/MichaelGrafnetter/DSInternals/tree/master

A collection of tools which integrate with Cobalt Strike
(and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
https://github.com/outflanknl/C2-Tool-Collection

Kernel mode WinDbg extension and PoCs for testing how token privileges work. https://github.com/daem0nc0re/PrivFu/tree/main

Malware dev Reading List
https://gist.github.com/0prrr/c0954a638c55ab4b39e8b02ef312e806
#maldev #malware_dev

💀
💀

Repost from Infosec Fortress
Hello again! I’m excited to announce a new feature in the plugin: it now supports regex-based searches. This means you can find instructions not just by their mnemonics, but also by using powerful regular expressions for more precise and flexible matching. The Repository link #projects ——— 🆔 @Infosec_Fortress

👀 don't miss this one
👀 don't miss this one

there is red-team workshop on 14 pm ( tehran time ) ( language -> persian ) mr.hashemi is going to talk about APT-38 it's goi
there is red-team workshop on 14 pm ( tehran time ) ( language -> persian ) mr.hashemi is going to talk about APT-38 it's going to be fun and a long workshop as he talking about all TTPs so فلاکس چای و خوراکی فراموش نشه :) access work shop here ( no registration needed ) : https://www.skyroom.online/ch/huntlearn/redteam