Source Byte
Відкрити в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Показати більше8 332
Підписники
-424 години
-97 днів
-5930 днів
Архів дописів
8 332
RedTeam Workshop - Part 4
* How do North Korean hackers bypass security mechanisms? *
APT38 attacks simulation , in this section, "defense evasion" was discussed.
Defense Evasion + T1562.003 | Impair Command History Logging + T1562.004 | Disable or Modify System Firewall + T1070.001 | Clear Windows Event Logs + T1070.006 | Timestomp + T1112 | Modify Registry + T1218.001 | Compiled HTML File + T1218.011 | Rundll32https://youtu.be/zDyPRrtXjus?si=265TY6KyElHGr-eR slides / notes : https://github.com/soheilsec/RT-workshop-2024 credit : @soheilsec language : persian
8 332
COM PROCESS INJECTION for RUST
Process Injection via Component Object Model (COM) IRundown::DoCallback().https://github.com/0xlane/com-process-inject.git
8 332
x64 WINAPI Recursive Loader
"Code provided by smelly - vx-underground"https://web.archive.org/web/20240928164510/https://github.com/Evi1Grey5/Recursive-Loader #Loader
8 332
The Anti-EDR Compendium
EDR functionality and bypasses in 2024, with focus on undetected shellcode loader.
https://blog.deeb.ch/posts/how-edr-works/
credit : Dobin Rutishauser
8 332
Repost from Order of Six Angles
Охуенная статья
Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation
https://blog.fox-it.com/2024/09/25/red-teaming-in-the-age-of-edr-evasion-of-endpoint-detection-through-malware-virtualisation/
8 332
Injecting Code into Windows Protected Processes using COM, Part 1 and Part 2 by James Forshaw of the Project Zero team prompted an interest in COM internals and, more specifically, the undocumented DoCallback method part of the IRundown interface.
- POC
#COM
8 332
Repost from Offensive Xwitter
😈 [ Check Point Research @_CPResearch_ ]
10 years of DLL hijacking - featuring abused executables that shouldn't have existed, exported and malicious DLLs with discount bin "packing." Includes a PoC for app developers to pre-emptively stop hijacking without dealing with a certificate authority.
🔗 https://research.checkpoint.com/2024/10-years-of-dll-hijacking-and-what-we-can-do-to-prevent-10-more/
🐥 [ tweet ]
8 332
Kimsuky Group's new backdoor appeared (HappyDoor)
https://web.archive.org/web/20240626161026/https://asec.ahnlab.com/ko/67128/
8 332
Repost from CyberSecurityTechnologies
#Red_Team_Tactics
"HookChain: A new perspective for Bypassing EDR Solutions", 2024.
]-> https://github.com/helviojunior/hookchain
8 332
Repost from 1N73LL1G3NC3
🥤 Pivoting using ZeroTier
🥤 Pivoting using Nebula
Demonstration of pivoting with ZeroTier and Nebula during the post-exploitation process. These tools showcase impressive capabilities such as flexible routing, NAT traversal, and the ability to build tunnels between isolated network segments, granting full access to internal infrastructure.
Thx to my bro @casterbyte
8 332
Process Injection via Component Object Model (COM) IRundown::DoCallback()
From MDSechttps://www.mdsec.co.uk/2022/04/process-injection-via-component-object-model-com-irundowndocallback/
8 332
Demystifying Windows Component Object Model (COM)
https://www.221bluestreet.com/offensive-security/windows-components-object-model/demystifying-windows-component-object-model-com
8 332
Lateral Movement using the MMC20.Application COM Object
First parthttps://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-object/
8 332
Repost from Infosec Fortress
A journey through KiUserExceptionDispatcher
🔗 Link
#windows
#reverse
———
🆔 @Infosec_Fortress
8 332
Repost from T00ls公开频道 | T00ls.com | 低调求发展,潜心习安全!
黑客组织 Twelve 针对俄罗斯实体发动破坏性网络攻击(作者:maojila)
黑客组织 Twelve 针对俄罗斯实体发动破坏性网络攻击
