Your EDR just coerced itself. 🫠
Drop a crafted LNK → MsSense.exe makes a CreateFile call → machine account hands over its Net-NTLMv2 hash over WebDAV → relay to LDAP → Shadow Credentials or RBCD.
No user interaction. No exotic exploit. Just vibes and a shortcut file.
If you're running Microsoft Defender for Endpoint, this one is literally about you. 👀
Full attack + detection breakdown 👇 https://t.co/wUsR1cHuZP
#purpleteam #MDE #NTLMcoercion #detectionengineering
Huginn Project:
Project to generate COFF-format shellcode with API for :
- Indirect syscall API
- Stack Spoofing
- Proxied LoadLibraryA calls
Great for UDRLs, stage0 and OPSEC-conscious shellcode.
https://t.co/tIiSlawD8K
Hello folks, inspired by @lefterispan , I’m releasing a BOF implementation of COM-Hunter for @_CobaltStrike. The BOF version includes the exact same features as the .NET implementation, and I recently added a remove-mode feature to both versions. I hope this BOF proves useful in your operations.
Project Link: https://t.co/NlcefTeOKn
#redtea #cobaltstrike #bof #beacon #persistence
Google research created a dataset with rainbow tables for NetNTLMv1 with the 1122334455667788 challenge.
https://t.co/fLBxwTIY2H
Dataset is available for download at:
▪️https://t.co/mCt6R7y5Pk [Login required]
▪️gs://net-ntlmv1-tables
Since several people already asked: the slides from @fabian_bader and myself for @WEareTROOPERS are available! "Finding Entra ID CA bypasses-the structured way". We talked about FOCI, BroCI, CA bypasses, scopes and getting tons of tokens. Check it at https://t.co/3oA2grfbO4
#HuntingTipOfTheDay: a personal favourite, command-line obfuscation. Substituting/inserting special Unicode characters might allow attackers to bypass string-based detections. Look for command lines with unusual Unicode characters. Checkout https://t.co/lVBYPiftK8 for more!
You have got a valid NTLM relay but SMB and LDAP are signed, LDAPS has got Channel Binding and ESC8 is not available... What about WinRMS ? :D
Blogpost: https://t.co/p2uwj2yKTQ
Tool: https://t.co/zMPpwtyFir
And also, big thanks to jmk (Joe Mondloch) for the collab' :D!
Microsoft has a huge list of portals and it is not always easy to keep track of all the naming changes, Therefore, this resource comes in very handy!
[LandingPage] MSPortals
https://t.co/CHptT44ph7
#Microsoft#LandingPage
I recently implemented 7 public UAC bypasses as BOFs and integrated them into a Havoc module and Sliver extensions. Requests to add more bypass methods are also welcome! https://t.co/Szg0ygwEg8
#100DaysOfYara Day 9: There are so many public rules out there, it's easy to lose track 🤯
I got you covered! In YaraToolkit v0.2, I added a search engine for some rules repositories. Just enter a keyword to find a specific rule 🔍
For now, it supports three public repos, but I'm open to adding more based on your suggestions! 🫶
👉 Check it out: https://t.co/d0UWC2XZN0
#Yara #infosec #malware
#infosec #yara #malware