w0rk3r's Windows Hacking Library
Kanalga Telegram’da o‘tish
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar42 664
1 663
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
Ma'lumot yo'q30 kun
Postlar arxiv
A C# penetration testing tool to discover low-haning web fruit via web requests
https://github.com/rvrsh3ll/SharpFruit
@WindowsHackingLibrary
How to bypass AMSI and execute ANY malicious Powershell code
https://0x00-0x00.github.io/research/2018/10/28/How-to-bypass-AMSI-and-Execute-ANY-malicious-powershell-code.html
@WindowsHackingLibrary
How to bypass UAC in newer Windows versions
https://0x00-0x00.github.io/research/2018/10/31/How-to-bypass-UAC-in-newer-Windows-versions.html
@WindowsHackingLibrary
Abusing PowerShell Desired State Configuration for Lateral Movement
https://posts.specterops.io/abusing-powershell-desired-state-configuration-for-lateral-movement-ca42ddbe6f06
@WindowsHackingLibrary
Reversing ALPC: Where are your windows bugs and sandbox escapes?
https://sandboxescaper.blogspot.com/2018/10/reversing-alpc-where-are-your-windows.html
@WindowsHackingLibrary
SMB Named Pipe Pivoting in Meterpreter
https://medium.com/@petergombos/smb-named-pipe-pivoting-in-meterpreter-462580fd41c5
@WindowsHackingLibrary
10 Red Teaming Lessons Learned Over 20 Years
https://www.oodaloop.com/ooda-original/2015/10/22/10-red-teaming-lessons-learned-over-20-years
@WindowsHackingLibrary
Slides: "If we win, we lose" - Using healthy competition to measure and improve security programs || BlueHat v18
https://www.slideshare.net/MSbluehat/if-we-win-we-lose-using-healthy-competition-to-measure-and-improve-security-programs
@BlueTeamLibrary
If we win, we lose
Tim MalcomVetter at BlueHat v18
https://www.youtube.com/watch?v=ifCeaYShRSU
@SecTalks
ADRecon - Detection CHCON 2018
https://speakerdeck.com/prashant3535/adrecon-detection-chcon-2018
@WindowsHackingLibrary
Another Word on Delegation
https://posts.specterops.io/another-word-on-delegation-10bdbe3cd94a
@BlueTeamLibrary
Invisi-Shell: Hide your Powershell script in plain sight. Bypass all Powershell security features
https://github.com/OmerYa/Invisi-Shell
@WindowsHackingLibrary
Goodbye Obfuscation, Hello Invisi-Shell: Hiding Your Powershell Script in Plain Sight
By Omer Yair at Derbycon
https://youtu.be/Y3oMEiySxcc
@SecTalks
Technical Rundown of WebExec
https://blog.skullsecurity.org/2018/technical-rundown-of-webexec
@WindowsHackingLibrary
SharpAttack: A console for certain tasks on security assessments. It leverages .NET and the Windows API to perform its work( and cobbr_io SharpSploit). It contains commands for domain enumeration, code execution, and other fun things.
https://github.com/jaredhaight/SharpAttack
@WindowsHackingLibrary
Powershell Payload Delivery via DNS using Invoke-PowerCloud
https://how.ired.team/offensive-security-experiments/payload-delivery-via-dns-using-invoke-powercloud
@WindowsHackingLibrary
Leveraging WSUS – Part One
https://ijustwannared.team/2018/10/15/leveraging-wsus-part-one
@WindowsHackingLibrary
[Tool] Icebreaker:
Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment
https://github.com/DanMcInerney/icebreaker
@WindowsHackingLibrary
