uk
Feedback
Source Byte

Source Byte

Відкрити в Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

Показати більше
8 154
Підписники
+2124 години
+707 днів
+31530 день
Архів дописів

With thanks to ZH54321

Pure PowerShell HTTP Server (no dependencies) Invoke-HttpServer
Pure PowerShell HTTP Server (no dependencies) Invoke-HttpServer

we already developed detection methods for this TA ....
we already developed detection methods for this TA ....

Repost from Unk9vvN
#puNK Lilith #RAT #Autolt گروه تهدید آسیای شرقی با نام puNK اخیرا حملاتی رو انجام داده است که نکات فنی مفیدی را میتواند داشته
+6
#puNK Lilith #RAT #Autolt گروه تهدید آسیای شرقی با نام puNK اخیرا حملاتی رو انجام داده است که نکات فنی مفیدی را میتواند داشته باشد. زنجیره حمله به این صورت بوده که یک فایل فرمت LNK به محض اجرا شدن، یک کد Powershell رو بر روی خط فرمان cmd بصورت مبهم سازی شده اجرا میکند. این اجرا موجب میشود یک فایل با نام Decoy دانلود و اجرا شود، اما در ادامه اجرای کد Powershell، یک فایل curl.exe دانلود و اجرا میشود که البته با نام تصادفی ساخته شده است، همچنین ساخت پوشه C:\GSILzFnTov و ریختن فایل اجرایی Autolt3.exe و فایل اسکریپت آن که با نام QwbpjvdmTA.au3 است. کد Powershell مرحله اول، بعد از دانلود و اجرای 2 فایل مرتبط با autolt3 بواسطه فایل curl.exe، یک Persistence نیز با schtasks.exe میسازد تا در یک بازه زمانی مشخص فایل بدافزار اجرا شود. بعد از اجرای بدافزار، مهاجم اقدام به سرقت نشست های Cookie مرورگر قربانی خواهد کرد. @Unk9vvN

SANS_Cheat-Sheet_windbg-pe-parsing.pdf6.32 KB

Mastering PE Parsing with WinDbg Speaker: Jonathan Reiter , 13 Jan Register : https://www.sans.org/webcasts/mastering-pe-parsing-windbg/

#SEC450 #FULL_COURSE #PERSIAN

Repost from /mdre/
Windows Authentication - Credential Providers - Part 1. A primer on writing a credential provider in Windows. ✨ Windows Authentication - Credential Providers - Part 2. Sequence of calls to a credential provider in Windows.

Repost from Infosec Fortress
Happy New Year 2025! Wishing you a year filled with joy, health, and success. 🎉🎄

cute 🥰

photo content

WTSRM - Writing Tiny Small Reliable Malware demo repository for my corresponding talk. Unhooks all Windows Dlls with \KnownDl
WTSRM - Writing Tiny Small Reliable Malware demo repository for my corresponding talk.
Unhooks all Windows Dlls with \KnownDlls\ No CRT dependencies Small size Low entropy Random string encryption key (thus no plaintext strings) API hashing Hook detection Walks around hooks for initial unhooking on ntdll
https://github.com/rad9800/WTSRM

WTSRM-SLIDES.pdf

NanoDump: How I Reinvented SafetyKatz to Dump LSASS with NanoDump https://xakep.ru/2024/11/13/lsass-nanodump/
NanoDump: How I Reinvented SafetyKatz to Dump LSASS with NanoDump https://xakep.ru/2024/11/13/lsass-nanodump/

Repost from Infosec Fortress
Exploit Development: No Code Execution? No Problem! Living The Age of VBS, HVCI, and Kernel CFG 🔗 Link #binary #exploitation #windows #hvci ——— 🆔 @Infosec_Fortress

Repost from Cʰᵃᵐʳᵒˢʰ
⭕️ Windows Drivers Reverse Engineering Methodology 🌐 Link 🌐 Github #malware_analysis #reverse_engineering @ch4mr0sh 🦹🏻‍♀
⭕️ Windows Drivers Reverse Engineering Methodology 🌐 Link 🌐 Github #malware_analysis #reverse_engineering @ch4mr0sh 🦹🏻‍♀