Joining Optiv back in 2020, Joey Belans was a huge mentor for me and helped me grow a TON.
I will always be grateful for his kindness. Joey was let go today from Optiv just before starting FMLA, and his family could really use support.
https://t.co/YkmC1Eug0k
Joey is such a good dude. First time I met him the guy was all smiles and good vibes. You'd haver never known what he was fighting internally. It's pretty unfortunate this situation and he and his family could really use some support right now. Please share for reach.
Home labs are one of the best tools for researchers & testers. @synzack21 shares a fully customizable #SCCM deployment that you can integrate into your home lab, creating a space for you to recreate SCCM research & probe for vulnerabilities. Read more! ⬇️ https://t.co/FCbOM4xWKe
Long overdue but SourcePoint v3.0 is out now, with a ton of new features and bug fixes. With these changes, Initial access and Post-Ex activities with CobaltStrike can fly under the radar.
Check it out https://t.co/RRqfMbS503 !
#redteam#netsec
SCCM Site takeover by abusing the AdminService API. In this blog, I walkthrough the discovery process and demonstrate site takeover via credential relaying.
https://t.co/pulvsxqbtA
Sharing a tool I wrote to streamline attacking SCCM. Some features include profiling target servers for admin smb relay attacks, site server takeover, http enrollment, and leveraging the adminservice api.
https://t.co/aiJzWIJNDR
New Tool - https://t.co/iCtru1F5d2 is a payload toolkit for bypassing EDRs using suspended processes, and direct syscalls written in RUST. Check it out: https://t.co/nd18QZW4AD #netsec#redteam#EDR#evasion#rustlang
ScareCrow 5.0 is out now, a massive rewrite of the framework with huge new features, IoC's removed & new evasion techniques added. If you are curious take a look at the changelog. Check it out: https://t.co/VIQVnKd2tJ #netsec#redteam#EDR#evasion
SysWhispers3 has been added to Shhhloader! 😎 It should work with all current shellcode injection techniques. Some bug fixes also make this the most stable version yet. More updates to come, and thanks to @KlezVirus for SW3. https://t.co/XZUXwvgw9G
I've had so much fun learning rust. This is an excellent example of the power of rust, no EDR unhooking, patching of ETW, syscalls, or LITCRYPT and it calls home against EDRs. More to come soon #redteam
I’m pleased to release Inline-Execute-PE, a CobaltStrike toolkit enabling users to load and repeatedly run unmanaged Windows exe’s in Beacon memory without dropping to disk or creating a new process each time. https://t.co/1byTo7uCV1
#redteam#cybersecurity#malware
Talon 3.1 is out today with some new features around password lock-out controls and other bug fixes. Big shoutout to ZerkerEOD for all the hard work.
#netsec#redteam
https://t.co/LeuW3jgoDR