I had a chance to share some thoughts in @FT on the flaws of our current security strategies. Sadly, many are still hyper focused on the illusion of a perimeter.
Want to obfuscate C# tools to evade signature-based detections on disk and in memory? Check out some research I did on this topic in an @xforcered blog post, including a POC obfuscation tool. https://t.co/erU2tNtYPf
Amazing, just noticed that SmuggleBus made it to GitHub’s Arctic Code Vault. For those new to the project, we’ll be showing a demo tomorrow (August 19) at #RedCon2020 virtual conference. Register and stream here: https://t.co/NggFFFYTvM
X-Force Red is hosting our own virtual conference on August 19th, register here: https://t.co/MQFu0oagNM
Among other great talks, the adversary simulation team will be showing off some awesome internal tooling by @FuzzySec
For those who may not have heard/read, @xforcered and I are hosting a virtual half day conference with some of the research we planned to put out at #hackersummercamp this year. Information and free registration here:
https://t.co/M4s9FH2GVj
The NTLMv1 multitool has been updated and merged into one tool
https://t.co/17XIz4jRHq
the new tool is python 2 and 3 compatible, and intelligently parses your hashes if they are NTLMv1
use python3 https://t.co/OBzMBN2WxZ --ntlmv1 "your ntlmv1 hash"
@NotMedic and @0x31337
الحمد لله، اكتشفت ثغرة في برنامج فيستايم بنظام ماك وتم تسجيلها وذكر اسمي في موقع شركة #ابل CVE-2019-8777
I discovered a vulnerability in #Facetime#macOS and @Apple mentioned my name in their #CyberSecurity update page and registered a CVE-2019-8777.
So, I managed to cram the LSASS and registry hive parsing capabilities of #pypykatz into webassembly via #pyodide
Parsing is fully offline and done in your browser.
Huge shoutout to @thugcrowd and @xEHLE_ who made the fancy webui for it and hosting it on their servers.
On Domain Controllers, LDAP Signing & LDAP Channel Binding become mandatory security settings.
https://t.co/CNI4qMe415
Test & Enable these before Microsoft Enables by Default:
https://t.co/S6mqkjXPQt
https://t.co/0KuzV3Pkja
#ActiveDirectorySecurity#activedirectorysecuritytips
releasing the materials (source, slides & lab guide) for the @defcon workshop by @olindoverrillo and I: Writing custom backdoor payloads with c#. Hope you can learn and have fun as much as we did.
https://t.co/tWCYq7ZV2k
@RajWarrior987 thx! i was doing some AMSI testing couple weeks ago and wrote a long overdue update for ps1encode. x64 bit support, shellcode XOR for signature bypass, prepend migrate by default, and new Golang encoder. Bypasses latest Defender AMSI as of release: https://t.co/L1TFJul45D
reminder: bettercap has a very convenient web ui that makes everything way easier, especially when running on mobile or headless on a RPI.
Install:
> sudo bettercap -eval "caplets.update; ui.update; q"
Run:
> sudo bettercap -caplet https-ui
https://t.co/Z8ZoNwXLXl
P4wnP1 A.L.O.A. - Framework Which Turns A Rapsberry Pi Zero W Into A Flexible, Low-Cost Platform For Pentesting, Red Teaming And Physical Engagements https://t.co/Fts7ZUIXF0