ZeroDayOps
Kanalga Telegramâda oâtish
đŠ Channel was restricted by Telegram
Ko'proq ko'rsatishMa'lumot yo'q
Obunachilar
-424 soatlar
-117 kun
-930 kun
Postlar arxiv
Bypassing Detections with Command-Line Obfuscation
Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executablesâ parsing âflawsâ, can bypass such detections. It also introduces ArgFuscator, a new tool that documents obfuscation opportunities and generates obfuscated command lines.
Bypassing Windows Defender Application Control with Loki C2
Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.
Persistence via App Registration in Entra ID
https://cyberdom.blog/persistence-via-app-registration-in-entra-id/
Releasing WebcamBOFđ¸
Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or screenshot). USB webcams supported (at least mine is)
Wazuh â Unsafe Deserialization RCE (CVE-2025-24016)
An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses. If an attacker injects an unsanitized dictionary into a DAPI request or response, they can craft an unhandled exception, allowing arbitrary Python code execution.
https://github.com/0xjessie21/CVE-2025-24016
StringReaper
CobaltStrike BOF designed to carve strings out of remote process memory. This tool allows operators to carve ASCII and UTF-16 strings from targeted processes, making it effective for retrieving JWT tokens, credentials, and other sensitive data directly from memory. Over the past 3 years i've had great success in using this tool on engagements. Saves time when oping from a C2 where you don't want to have to wait on a full process dump or deal with download size issues.
+2
CVE-2025-21298: A Critical Windows OLE Zero-Click Vulnerability
https://www.offsec.com/blog/cve-2025-21298
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx
A few years ago, James Forshaw discovered a technique allowing to perform Kerberos relaying over HTTP by abusing local name resolution poisoning. In this article, we present the attack and propose a concrete implementation through the Responder and krbrelayx tools.
Repost from APT
đť Elevation of Privilege via Network Configuration Operators (CVE-2025-21293)
This article discusses a vulnerability in Active Directory (CVE-2025-21293) related to the Network Configuration Operators group, which has excessive permissions to create subkeys in the registry for DnsCache and NetBT. This allows attackers to leverage Performance Counters to execute code with NT\SYSTEM privileges, potentially leading to privilege escalation.
đ Source:
https://birkep.github.io/posts/Windows-LPE/
#ad #network #group #lpe #cve
ReverseShell_2025_01.ps1
New PowerShell reverse shell, currently undetected by AV systems (Usually valid for 1â2 weeks before detection). Bonus: AI defenses bypassed with a single additional line
Go Defender
Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.
AdaptixC2
An extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and the GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS operating systems.
Features:
⢠Server/Client Architecture for Multiplayer Support ⢠Cross-platform GUI client ⢠Fully encrypted communications ⢠Listener and Agents as Plugin (Extender) ⢠Client extensibility for adding new tools ⢠Task and Jobs storage ⢠Files and Process browsersDocumentation
Azure Attack Paths
In this blog article I want to shed some light on known attack paths in an Azure environment. The attacks are not new to many, and I relied on public research from other IT security professionals while writing this article.
Repost from Offensive Xwitter
đ [ MrAle98 @MrAle_98 ]
Finally finished to develop an exploit for CVE-2024-49138: vulnerability in CLFS.sys.
I'll provide a detailed analysis in a blog post.
đ https://github.com/MrAle98/CVE-2024-49138-POC
đĽ [ tweet ]
emp3r0r
A post-exploitation framework for Linux/Windows
emp3r0r C2 (Linux/Windows) is ready for testing. Please report bugs if you find any.
Read wiki to get started
Download from here
Write modules for emp3r0r with your favorite languages
Windows support is ready with fully-interactive shell
Hey everyone,
Can someone tell me why I am no longer recommended in the similar channel?
@zerolmk
RustPotato
A Rust implementation of GodPotato â abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.
PANIX
is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
