Exciting times. I'm publishing Dittobytes today after presenting it at @OrangeCon_nl !
Dittobytes is a true metamorphic cross-compiler aimed at evasion. Use Dittobytes to compile your malware. Each compilation produces unique, functional shellcode.
https://t.co/761G96JDF1
BYOVD is no longer required on modern Windows. a bunch of recent msft kernel patches just shove vulnerable kernel code behind a privilege check. I wonder if we will see threat actors leveraging this like they did BYOVD. no bringing along a driver and loading also means less IOCs
@SpecterOps#socon2025 is wrapping up today. If you were not there or if you want to revisit these new Sandbox Bypasses and TCC escalation: https://t.co/9AGXRSE5WV.
There is a bonus technique not included in the talk 👀
Hear about several practical attack techniques that can be used to improve your Red Team simulations. Join @ThiagoMayllart's session starting now at #SOCON2025!
From classic HTML pages to advanced MFA bypasses, dive in with @_atsika in an exploration of phishing techniques 🎣.
Learn some infrastructure tricks and delivery methods to bypass common detection.
👉https://t.co/zkhi1RxnDk
(promise this one is legit 👀)
Today I'm releasing Xenon, a custom Mythic agent for Windows targets written in C.
Notable features include:
📁 Modular command/code inclusion
🦠 Malleable C2 Profile support
🪨 Compatible with Cobalt Strike BOFs
https://t.co/oiKbSpwA7A
Blog series -
https://t.co/o3QLbHyzzt
Troll, but Verify: Security Lessons From North Korean Job Candidates by Thiago Silva & Michael Be from @krakenfx!
Kraken is one of the largest centralized exchanges. In 2024, we received multiple pieces of intelligence identifying candidates as associated with the DPRK's cyber operations group.
Full video below 👇🧵
When researching Palo Alto PAN-OS, @assetnote's Security Research team discovered an authentication bypass due to flaws in its architecture. Our team digs a lot deeper than surface-level CVEs; this research is an example. https://t.co/sJKwoovhFk
Don't miss @ThiagoMayllart's talk at #SOCON2025! Register today so you can join his talk delving into several practical attack techniques that can be used to improve your Red Team simulations.
Check out more talks & register ➡️ https://t.co/LmM2H1ZME7
In his new post, @jaredcatkinson examines how changing the implementation of tradecraft can have as much of an impact on detection programs as changing the behavior.
Read more ⤵️ https://t.co/gKsHNLXLLi
Without further ado - here is EtwInspector!
This is a C++ tool to help users interact with ETW providers. This tool supports the enumeration of providers, their events, and capture events.
https://t.co/gHXRCHxAv1
I'm intending to release an open-source Visual Studio Code extension to make writing BOFs easier for the community:
- Complete Nt/Zw function prototypes with tab completion (and correct typecasting for placeholder variables)
- MSDN header searching
PoC:
https://t.co/tNc4WCLB6c
Spencer created something that's very unique with Mythic - he created Mythic agents that use Mythic's API and Sliver's API to remotely control Sliver agents from within Mythic. He even hooked it into Mythic's File/Process Browsers! Check it out! https://t.co/J75ac6de1u