w0rk3r's Windows Hacking Library
Kanalga Telegram’da o‘tish
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar42 664
1 663
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
Ma'lumot yo'q30 kun
Postlar arxiv
Icebreaker.py: Gaining a foothold in Active Directory in one command
Dan McInerney at SaintCon
https://youtu.be/1LR5u8uKO8I
@SecTalks
MicroBurst: A collection of scripts for assessing Microsoft Azure security
https://github.com/NetSPI/MicroBurst
@WindowsHackingLibrary
Attacking Azure Environments with PowerShell
https://youtu.be/IdORwgxDpkw
@SecTalks
Exploiting Regedit: Invisible Persistence & Binary Storage
https://github.com/ewhitehats/InvisiblePersistence/blob/master/InvisibleRegValues_Whitepaper.pdf
@CyberWhitePapers
Operating Offensively Against Sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
@WindowsHackingLibrary
ServiceFu: Harvesting Service Account Credentials Remotely
https://www.securifera.com/blog/2018/10/07/servicefu
@WindowsHackingLibrary
Malicious use of Microsoft “Local Administrator Password Solution”
http://archive.hack.lu/2017/HackLU_2017_Malicious_use_LAPS_Clementz_Goichot.pdf
@WindowsHackingLibrary
Time Travel Debugging: finding Windows GDI flaws
https://www.pentestpartners.com/security-blog/time-travel-debugging-finding-windows-gdi-flaws
@WindowsHackingLibrary
Creating Persistence with DCShadow
https://blog.stealthbits.com/creating-persistence-with-dcshadow
@WindowsHackingLibrary
invoke-Confusion .NET attacker of Powershell Remotely
https://homjxi0e.wordpress.com/2018/10/02/invoke-confusion-attack-of-powershell
@WindowsHackingLibrary
Domain Controlller Print Server + Unconstrained Kerberos Delegation = Pwned Active Directory Forest
https://adsecurity.org/?p=4056
@WindowsHackingLibrary
Abusing Windows Library Files for Persistence
https://www.countercept.com/blog/abusing-windows-library-files-for-persistence
@WindowsHackingLibrary
The power of backup operators
https://decoder.cloud/2018/02/12/the-power-of-backup-operatos
@WindowsHackingLibrary
PowerShell: Documenting your environment by running systeminfo on all Domain-Computers
https://sid-500.com/2017/08/09/powershell-documenting-your-environment-by-running-systeminfo-on-all-domain-computers
@WindowsHackingLibrary
Responder and Layer 2 Pivots
https://ijustwannared.team/2017/05/27/responder-and-layer-2-pivots
@WindowsHackingLibrary
Injdrv is a proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
https://github.com/wbenny/injdrv
@WindowsHackingLibrary
AppLocker CLM Bypass via COM
https://www.mdsec.co.uk/2018/09/applocker-clm-bypass-via-com
@WindowsHackingLibrary
Tokenvator: Release 2
https://blog.netspi.com/tokenvator-release-2
@WindowsHackingLibrary
