Reminder ❗️
You can avoid XOR operations to obfuscate a .net assembly/PE buffer by implementing MUL + ADD operations.
If you are wondering: no, you don't need to write asm code.
You can have a look at SharPyShell ulong compression obfuscation that is a C# implementation ;)
Classic example of insider threat. A cleaner at Israeli Defense Minister Benny Gantz's home has been charged with espionage after allegedly offering BlackShadow, an Iran-linked hacker group, to plant malware on the defense minister's computer. https://t.co/TAVUoGNIEz
Part 3 of our Kernel Karnage blog series is now live! 🔥
In this post, @cerbersec takes on another AV. Want to see if he can win this fight as well? Check out https://t.co/YHwZ48wJ3i
#kernel#bypass#av#redteam#driver#os#windows
Mimikatz's DCSync and DCShadow commands generate detectable network traffic. Learn more in our latest blog post!
"Detecting DCSync and DCShadow Network Traffic" by @DidierStevens
https://t.co/Aqcaiedllz
Interested in these topics? This and much more is discussed in #SEC599!