New writeup:
"Hacking Millions of Modems (and Investigating Who Hacked My Modem)"
https://t.co/VZbWEIF5I8
Thanks for reading! Huge thanks to @blastbots, @bbuerhaus, @infosec_au, @d0nutptr, @iangcarroll, and everyone who reviewed the post beforehand.
I'm intending to release an open-source Visual Studio Code extension to make writing BOFs easier for the community:
- Complete Nt/Zw function prototypes with tab completion (and correct typecasting for placeholder variables)
- MSDN header searching
PoC:
https://t.co/tNc4WCLB6c
GIANT merge to Nemesis just published
If you've ever struggled to install Nemesis, we've made it 10x easier by getting rid of nemesis-cli and using Helm for k8s management instead
Check out the new setup guide for instructions on how to install: https://t.co/ZGuAmIC9Uv
I had a bit of spare time and managed to recreate this, but SharedOriginal winning again...
It amazes me how this is so simple and yet so effective. Really a great finding.
Modern implant design: position independent malware development.
A small blog post on how to design "modern" malware with features like global variables, raw strings, and compile-time hashing.
https://t.co/Drz7kcVhyK
Repo: https://t.co/S7h7QY9bXY
What is Loader Lock? 🤔 Going BEYOND undocumented, we delve into the heart of the modern Windows loader investigating some internals for the first time and demystifying Loader Lock. 🔒 Check out the research article
https://t.co/q98cfTJYIM
It's been a long time coming, but JonMon is finally here. This has been something I have worked on for a while. I hope the community enjoys it and I am happy to hear any feedback anyone has!
Slides can be found: https://t.co/pNDeP9u1Do
GitHub: https://t.co/LA77K2F8RB
Introducing deep-TEMPEST: a deep learning method that recovers great quality images from unintentional electromagnetic emanations of HDMI. Great work (in progress) by E. Martinez, S. Fernandez and G. Varela 💪💪 (co-mentored with @muse_pablo). Expect more news in the next weeks.
My Okta for Red Teamers post is up! We look at how Kerberos SSO works, how to intercept credentials via a fake AD Agent, decrypting AD Agent tokens, adding skeleton key's, and even how to deploy a janky SAML IdP server to auth as any user for good measure. https://t.co/Hs0wN5397s
Chrome just announced that it will be using my browsing history to show me ads. I’m really glad I don’t use Chrome as my main browser, and I wish other folks would stop this.
[BLOG]
Ok, I've written about my experience of battling with both managed and unmanaged memory allocations to try and improve @FuzzySec's Melkor POC.
https://t.co/UHNS2siwjA
Hooks without custom exception-handler or changing memory protection?
@x86matthew: hold my beer!
Introducing StealthHook - controlling the execution flow of the target function by intercepting return addresses in the nested function call stack.
https://t.co/j0OGCT00Hq
I’m excited to announce that my book, “Evasive Malware”, will soon be available for pre-order! The past 2.5 years of late nights, eye strain, and carpal tunnel is almost worth it 😎
Also excited to announce that my technical reviewer is the amazing @fr0gger_ !
Stay tuned! 👇
Today, we are releasing RPC Investigator, made for exploring RPC clients and servers on Windows. This .NET application builds on the NtApiDotNet platform, adding features that offer a new way to explore RPC https://t.co/8cfBAMdrux
[RELEASE] After a little wait, I'm happy to present SilentMoonwalk, a PoC implementation of a TRUE call stack spoofer, result of a joint research on an original technique developed by namazso, done with my friends @trickster012 and @waldoirc.
Enjoy! ;)
https://t.co/C5QBzNawza
Welcome to the new AD Mindmap upgrade !
v2022_11 will be dark only (this is too painful to maintain two versions).
Thx again to : @Vikingfr and @Sant0rryu for their help 👍
Full quality and zoomable version here :
https://t.co/eIJE0apRzw
Overview :
HavocNotion - Super simple ExternalC2 PoC for Havoc C2 to C2 over Notion API
Accompanying blogpost like before will be posted soon when I have time
https://t.co/W73ul42BhH
Was updating my build toolchain and realized I was up a creek trying to get msvcrt linking to work without some hacky workaround. Awesome guide by @SolomonSklash, thanks for saving me the headache!
https://t.co/k4LlpEa20L