Had an amazing experience attending .NET Exploitation with Sina Kheirkhah @SinSinology, hosted by BSides Tirana @BSidesTirana! Great content on .NET static and dynamic reverse engineering, obfuscation, and serialization/deserialization. Bought 2 books already...
NEED YOUR HELP!
My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,...
but companies keep saying:
"we aren't hiring right now!"
if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team
you're retweet is Extremely appreciated ❤️🔥
soroush, if you see this, don't hate me, had to do it without telling you
Only 7 days left until the event day, I would like to invite everyone to register 💫
The conference is free and everyone is welcome👏🏻
BSides Tirana Main Conference Registration Link:https://t.co/OJqYdJ2ZeP
Code in C is straight forward:
- Hardcoded AES encrypted payload
- VirtualAlloc, VirtualProtect, CreateThread
- Change extension to .log
Wanting to experiment more with a full blown EDR/XDR by focusing on detection once EDR is bypassed.
Local process injection with AES payload encryption and .log file extension managed to bypass Defender in full patched Win10.
Well aware, this payload will not succeed against a proper EDR/XDR, I am looking if any vendor might offer a free developer license for research purpose.
Recently completed the "Hands-On Kusto Query Language (KQL) for Security Analysts" course by Blu Raven and was impressed by its quality. The training, especially Anomaly Detection and Time Series Analysis sections, is perfectly tailored to the unique needs of security analysts.
The practical examples and current content make it an invaluable resource for staying ahead in the ever-evolving threat landscape. The dataset used in the course is just incredible. I've never seen such realistic data in a training course, it feels like working in a real SOC.