w0rk3r's Windows Hacking Library
Kanalga Telegram’da o‘tish
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar42 664
1 663
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
Ma'lumot yo'q30 kun
Postlar arxiv
Using Kerberos for Authentication Relay Attacks
https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html
@WindowsHackingLibrary
Dechaining Macros and Evading EDR
https://blog.f-secure.com/dechaining-macros-and-evading-edr
@WindowsHackingLibrary
OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers
https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
@WindowsHackingLibrary
Empirically Assessing Windows Service Hardening
https://www.tiraniddo.dev/2020/01/empirically-assessing-windows-service.html
@WindowsHackingLibrary
The dying knight in the shiny armour: Killing Defender through NT symbolic links redirection while keeping it unbothered
https://aptw.tf/2021/08/21/killing-defender.html
@WindowsHackingLibrary
Zoom RCE from Pwn2Own 2021
https://sector7.computest.nl/post/2021-08-zoom
@WindowsHackingLibrary
Breaking Typical Windows Hardening Implementations
https://www.trustedsec.com/blog/breaking-typical-windows-hardening-implementations
@WindowsHackingLibrary
A New Attack Surface on MS Exchange Part 2 - ProxyOracle!
https://blog.orange.tw/2021/08/proxyoracle-a-new-attack-surface-on-ms-exchange-part-2.html
@WindowsHackingLibrary
A New Attack Surface on MS Exchange Part 1 - ProxyLogon!
https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html
@WindowsHackingLibrary
ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
Orange Tsai at DEFCON 29
https://www.youtube.com/watch?v=5mqid-7zp8k
@SecTalks
ForgeCert: "ForgeCert uses the BouncyCastle C# API and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication to Active Directory."
https://github.com/GhostPack/ForgeCert
@WindowsHackingLibrary
Certified Pre-Owned: Abusing Active Directory Certificate Services (Slides)
https://www.slideshare.net/harmj0y/certified-preowned-249927533
@WindowsHackingLibrary
Stealing Tokens In Kernel Mode With A Malicious Driver
https://www.solomonsklash.io/stealing-tokens-with-malicious-driver.html
@WindowsHackingLibrary
From Stolen Laptop to Inside the Company Network
https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-inside-the-company-network
@FromZer0toHero
MachineAccountQuota is USEFUL Sometimes: Exploiting One of Active Directory's Oddest Settings
https://www.netspi.com/blog/technical/network-penetration-testing/machineaccountquota-is-useful-sometimes
@WindowsHackingLibrary
Cobalt Strike and Tradecraft
https://hausec.com/2021/07/26/cobalt-strike-and-tradecraft
@BlueTeamLibrary
Hijacking DLLs in Windows
https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows
@WindowsHackingLibrary
Windows Command-Line Obfuscation
https://www.wietzebeukema.nl/blog/windows-command-line-obfuscation
@WindowsHackingLibrary
Fantastic Windows Logon types and Where to Find Credentials in Them
https://www.alteredsecurity.com/post/fantastic-windows-logon-types-and-where-to-find-credentials-in-them
@WindowsHackingLibrary
