New #redteam tool for blocking EDRs: EDRChoker
Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events
#pentest #cybersecurity
Github: TwoSevenOneT/EDRChoker
For a report I've submit report to MSRC months ago, showed full remote capabilities.
MSRC closed saying it's "Local only".
I comment: "I showed a 0 click proof of concept here. Why was it closed?"
MSRC:" The assessment decision remains unchanged."
Me:"Ok but I proved remote with X PoC and you can see the video I've even attached a few months ago that shows it in action"
MSRC: " Please feel free to submit a new report with additional details."
Yeah, nah. Big L for Microslop. Nobody has a moral obligation to hand over their hard earned discoveries for free. Pay up or shut up. You are owed nothing, and you will get nothing by stomping your feet like a petulant child because “[this is] an “unnecessary risk” that forced its security teams to work around the clock, to understand, protect customers and develop patches.”
God forbid your people do their jobs and it cost you more money than paying the researcher. Good.
I suggest anyone either disclose them publicly to light a fire under Microsoft’s ass or keep them to yourself. Make them feel the pain of not paying out appropriately to save them time. They have pulled the “doesn’t meet servicing criteria” then patch it next update one too many times for valid bugs.
RE:
https://t.co/prMIqJAkes
Microsoft "patched" a Windows bug in December 2020 that lets a standard user write to protected parts of the system that only SYSTEM should have access to. Basically you can take over the machine from a normal account.
I just built the new exploit for it and ran it on my Windows 11 machine. Still works. Over 5 years later.
Hunting Chinese APTs Abusing Native Windows Tools
We covered several ways Chinese APT groups abuse LOLBins based on findings from Mandiant reports. We also included Sigma rules and demonstrated how to convert them for use with your SIEM solution.
https://t.co/2Xbzdq1UHO
@three_cube@_aircorridor #dfir #apt
Big news for Blue Team nerds
That nerd who released those Microsoft 0days has created two new repos on GitHub with spooky sounding names indicating they will be releasing two new Windows 0days.
Very cool
https://t.co/VaWFtW5lFi