uk
Feedback
w0rk3r's Windows Hacking Library

w0rk3r's Windows Hacking Library

Відкрити в Telegram

Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r

Показати більше
Країна не вказанаТехнології та додатки42 664
1 663
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів

Telemetry Sourcerer can enumerate and disable common sources of telemetry used by AV/EDR on Windows. https://github.com/jthuraisamy/TelemetrySourcerer @WindowsHackingLibrary

Extending the Exploration and Analysis of Windows RPC Methods Calling other Functions with Ghidra, Jupyter Notebooks and Graphframes https://medium.com/threat-hunters-forge/extending-the-exploration-and-analysis-of-windows-rpc-methods-calling-other-functions-with-ghidra-e4cdaa9555bd @WindowsHackingLibrary

SIGRed – Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers @WindowsHackingLibrary

A Guide to Reversing and Evading EDRs Part 1: Introduction http://jackson-t.ca/edr-reversing-evading-01.html Part 2: Sensor Reconnaissance http://jackson-t.ca/edr-reversing-evading-02.html Part 3: Diverting EDR Telemetry to Private Infrastructure http://jackson-t.ca/edr-reversing-evading-03.html @WindowsHackingLibrary

"Heresy's Gate": Kernel Zw*/NTDLL Scraping + "Work Out": Ring 0 to Ring 3 via Worker Factories https://zerosum0x0.blogspot.com/2020/06/heresys-gate-kernel-zwntdll-scraping.html @WindowsHackingLibrary

Group Policies Going Rogue GPSVC exposes all domain-joined Windows machines to an escalation of privileges (EoP) vulnerability. https://www.cyberark.com/resources/threat-research-blog/group-policies-going-rogue @WindowsHackingLibrary

NINA: x64 Process Injection: (No Injection, No Allocation x64 Process Injection Technique.) https://undev.ninja/nina-x64-process-injection @WindowsHackingLibrary