New #redteam tool for blocking EDRs: EDRChoker
Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events
#pentest #cybersecurity
Github: TwoSevenOneT/EDRChoker
In my latest blog "Now You See Me: AADGraphActivityLogs" I explore the newly released Azure AD Graph logs and demonstrate how you can detect tools like ROADtools and AADinternals that rely on this API and have been under the radar for defender so far.
https://t.co/TXlkbsqKHa
''GitHub - p0dalirius/ShareHound: A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily''
#infosec#pentest#redteam#blueteam
https://t.co/WRf4ZRrYpp
DarkGate - a modular persistent malware with evasion and creds collection capabilities.
A post by Sapir Twig.
Source: https://t.co/L3wo9wJLoX
#redteam#blueteam#maldev#malwaredevelopment
MorphKatz
MorphKatz rewrites x86-64 machine code inside PE executables and raw shellcode into semantically identical but byte-different equivalents
https://t.co/DQxO5KtPL6
#forensics#evasion#pentesting