Red Team Tip:
'explorer.exe /root' can be run from the command line - similar to 'cmd.exe /c', only it breaks the process tree and makes its parent a new instance of explorer
For blue team: keep an eye on multiple instances of explorer.
explorer.exe /root,"D:\CyberRaiju.exe"
First blog post on how to automatically rewrite 700'000 lines of code to bypass most AV/EDR (features string+API call obfuscation for Meterpreter): https://t.co/O9xGB09at0
Cmd Hijack !!!
A command/argument confusion issue with path traversal bug in Windows cmd.exe
https://t.co/GlD1323xfz
cmd.exe /c "ping 127.0.0.1/../../../../../../../../../../windows/system32/calc.exe"
via @julianpentest
For everyone wondering how spam events got added to your Google Calendars without having a source in your inbox @ustayready and myself talked and wrote about how the Google Calendar API can be used to do this two years ago when we reported it to Google. https://t.co/g0Aip263cZ
North Korean hackers from Kimchaek University of Technology, who was dispatched to India and engaged in hacking activities, are believed to have recently moved to Cambodia.
#redteam tip, ifu plan to persist via scheduled task, give a try to hijack this MS Office related task (got created and deleted automatically by office integrator.exe), task xml file can be edited if u have local admin (same folder host other tasks), otherwise try to mimic same