Source Byte
Открыть в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Больше8 185
Подписчики
+1824 часа
+997 дней
+36030 день
Архив постов
8 186
post updated :
part 21 added
Getting started with Event Tracing for Windows in C#
credit : Alex Khanin
https://medium.com/@alexkhanin/getting-started-with-event-tracing-for-windows-in-c-8d866e8ab5f2
8 186
Bypassing PESieve and Moneta (The "easy" way....?)
It contains several parts.
Lockd: This is the main Gargoyle component
sRDI-Master: This has been slightly re worked to provide a free mechanism.
test.profile: This sample profile shows required options to work
ShellcodeRDI.py: This is the altered python generator with the new sRDI assembly
Blog
GitHub
#maldev
8 186
Repost from APT
🌀Voidgate
A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes by performing on-the-fly decryption of individual encrypted assembly instructions, thus rendering memory scanners useless for that specific memory page.
🔗 Source
https://github.com/vxCrypt0r/Voidgate
#av #edr #evasion #hwbp #cpp
8 186
Repost from Order of Six Angles
PE-LiteScan (or PELS) is a simple heuristic analyzer for common PE-anomalies, specifically focusing on the detection of packers and protectors. Designed for Windows and Linux.
https://github.com/DosX-dev/PE-LiteScan
8 186
updated : part 19 & 20 added
- New Perspectives on ETW Patching Telemetry
- Malware academy :
( modules 12 - 17 )
+ Event Tracing For Windows - Introduction + Event Tracing For Windows - ETW Tools + Event Tracing For Windows - ETW Bypass Via Byte Patching + Event Tracing For Windows - Improved Patching + Event Tracing for Windows - Patchless ETW Bypass Via HBPs + Event Tracing For Windows - ETW Provider Session Hijacking
8 186
guys if anyone have this maldev academy modules will be great to share them on the group so i can add and make this ETW series more complete :)
8 186
Repost from Cafe Security
The art of Fuzzing: Introduction
https://bushido-sec.com/index.php/2023/06/19/the-art-of-fuzzing/
@cafe_security
8 186
Repost from Infosec Fortress
Cindy Xiao - Reversing Rust Binaries
#binary
#reverse
#slides
———
🆔 @Infosec_Fortress
8 186
Repost from Infosec Fortress
Skochinsky - Recon (2011) - Practical C++ Decompilation
#reverse
#binary
#slides
———
🆔 @Infosec_Fortress
8 186
new process injection technique called
Mockingjay allows attackers to stealthily execute malicious code
https://wins21.co.kr/kor/promotion/information.html?bmain=view&language=KOR&uid=4037
#injection8 186
Repost from S.E.Book
👾 Malware Development - Evading Diaries.
• NTFS Files Attributes;
• FuncIn;
• Code Cave;
• Stolen Certificate;
• Redirect Antivirus Website Evading Techniques;
• Shortcut Hiding;
• Disabling Antivirus;
• Adding Antivirus Exception;
• Fake Signature;
• Mark-Of-The-Web (MOTW) Bypass;
• Return Address Spoofing;
• Runtime Function Decryption;
• DLL Unhooking;
- How DLL Unhooking Works;
- Unhooking Strategies;
• Evasion Using Direct Syscalls;
- Key Aspects of This Technique;
- Operational Mechanism;
- Featured Windows APIs;
• Unloading Module With FreeLibrary;
- Operational Overview;
- Key Aspects of This Technique;
- Featured Windows APIs;
• References.
#Malware
8 186
Repost from کانال بایت امن
#eBook #WindowsPE #DWORD
🏳️باز نویسی و ترجمه کتاب Windows PE权威指南
🔥 این کتاب بهطور جامع و مفصل به تحلیل فرمت فایل PE و تکنیکهای برنامهنویسی مرتبط با آن میپردازد و جنبههای مختلف امنیتی و مدیریت پروسس های سیستمی و مکانیسمهای سطح پایین آن را مورد بررسی قرار میدهد.
با توجه به تاریخ انتشار کتاب Windows PE权威指南 که به زبان چینی و در سال 2011 به چاپ رسیده است، در بازنویسی این کتاب سعی کردهام مطالب و ابزارهای قدیمی را حذف کنم و از نرمافزارهای به روز و مطالب جدید استفاده کنم. به همین دلیل ممکن است بعضی از موضوعات بهطور کامل تغییر یا جایگزین شوند و یا حتی بر حسب نیاز مطالب جدیدی اضافه گردند.
سطح مطالب این کتاب پیشرفته است و موضوعاتی که مطرح میشوند ممکن است نیاز به داشتن پیشنیاز باشند. به طور مثال، کدنویسی پروژهها به زبان اسمبلی و در محیط برنامهنویسی انجام میشود، بنابراین شما باید زبان اسمبلی را بدانید و با محیط برنامهنویسی به زبان اسمبلی آشنایی داشته باشید. تمرکز این کتاب بر تشریح ساختار فایلهای PE خواهد بود و به آموزش پیشنیازها یا سایر موارد اشاره نخواهیم کرد. با این حال، در هر فصل بخشی تحت عنوان منابع وجود دارد که برای درک و آشنایی بیشتر شما با بعضی مطالب، منابع مناسبی معرفی خواهند شد.فصل اول : محیط توسعه Windows PE تعداد صفحات : 29 صفحه 💎دریافت فصل اول | گیتهاب کتاب 🦅 کانال بایت امن | گروه بایت امن _
8 186
Repost from zerodaytraining
Patch candidate for Oracle VirtualBox VirtIOCore Buffer Overflow Local Privilege Escalation Vulnerability (Pwn2Own Vancouver 2024 VM Escape exploit)
There was an insufficient check for numbers of in/out data segment descriptors supplied by Guest OS into Virtio devices. Check added in virtioCoreR3VirtqAvailBufGet IO processing loop ensures that data sent in by the guest through virtio kernel device modules cannot exceed storage availability in hypervisor memory. Exploit by overflowing buffers in pVirtqBuf-aSegsIn/aSegsOut
@thezdi @OnlyTheDuck @alisaesage
