Source Byte
Відкрити в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Показати більше8 378
Підписники
-324 години
+327 днів
+29330 день
Архів дописів
8 378
Building Something EDR-like with Rust×eBPF
https://speakerdeck.com/sunlife3/rustxebpf-de-edr-ppoi-mono-o-tsukuru
8 378
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF
#CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023. However, Nebula Security discovered a bypass of the patch and found that it is actually exploitable and can lead to LPE on any Linux distribution that has IPv6 and namespaces enabled. This writeup covers the technical details of the exploit.
https://nebusec.ai/research/cve-2026-43501-route-of-root/
8 378
Repost from N/a
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
8 378
Repost from N/a
🔓 Dumping NTLM Hashes from Windows Memory via forensics tools
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored: WinPmem → Volatility 3 → SYSTEM/SAM → NTLM#RedTeam #OffensiveSecurity
8 378
Repost from N/a
گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسی
اینجا قراره ریپورتهایی که منتشر میشه رو بررسی کنیم، تکنیکهای جدید رو استخراج کنیم و دربارهی مشکلات فنی و چالشهایی که سر راه اجراست بحث کنیم.https://t.me/+drFBtbbrVDo5NjA0
8 378
فارغ ازینکه sysmon قابلیت جمع اوری چه تلمتری هایی رو داره باید گفت سایتی که استفاده شده متاسفانه فاقد هرگونه دیتیل فنی هست و بیشتر جنبه تبلیغاتی داره
به طور مثال پادویش در رتبه بهتری از trend micro و bitdefender و carbon black قرار داره 😕
https://www.edr-telemetry.com/scores
8 378
FirmBurn:How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks
FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting Dell EMC storage systems.
https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/
8 378
Repost from N/a
Red Team Engineering 2026
Info : https://nostarch.com/red-team-engineering
#redteam
8 378
ODR: Internals of Microsoft's New Native MCP Registration
https://www.originhq.com/research/msft-odr-mcp
