Cyllex v0.4.0:
604 TTPs across 7 platforms. Full Azure & GCP cloud coverage, Kubernetes & Docker container testing, 4 SIEM integrations, and 21 APT group profiles in the new APT Codex.
Beta is targeting late March / early April. I track progress publicly, you can see exactly where things stand at any point.
One last thing:
thank you. Building this solo takes time, and knowing people are actually following along makes it worth it. Every subscription, every piece of feedback, every message asking about the beta reminds me why I started this in the first place. Genuinely appreciate the support.
#purpleteam #cyllexframework #aptemulation #mitre #attacksimulation
Big update!,
• Events ID added to all the TTPs
• SIEM correlation actually works end-to-end now. Splunk, Sentinel, and AWS SecurityHub integrated
• Verify detections directly from the Campaigns panel
• Run queries from within the framework itself, no need to jump between tools
More news coming soon
Spent the weekend working on Cyllex and added a Splunk integration for log correlation. Also added detection events for each TTP. There's still a lot of work ahead, but it's starting to look great! I'll keep working on more integrations.
Thanks to everyone who's been showing interest and supporting the project! :)
@cyllexframework
Introducing: GhostKatz! 🐱
A Cobalt Strike BOF that lets you dump LSASS via exploitation of vulnerable drivers that offer physical memory read primitives.
Written by @EricEsquivel123 and I!! :)
https://t.co/tmuksIKvj8
Reversing a Microsoft-Signed Rootkit: The Netfilter Driver - Reverse Engineering Attempts.
Author: @Splintersfury
Great detailed write-up. If anyone interested in driver reversing, do check his work out. 🫡🔥 https://t.co/pSm6GZzvk2
Discovering PPL Protection in Windows Processes
New Medium post! Today, we’re exploring the classic method for identifying the Protected Process Light (PPL) status
https://t.co/E5tHbkmdMT
Hey everyone! 👋
I tried putting together some sigma rules to detect Notepad++ updater (GUP.exe) Infrastructure abuse attack.
Feel free to check out and give them a try. Any feedback is highly appreciated.
https://t.co/D37LrH7LVX
The upcoming Malware Development course update will focus on persistence.
The demo video below, part of our WMI persistence module, demonstrates achieving persistence when Microsoft Defender performs a signature update attempt.
Spent some time porting DumpGuard to C as a BOF. Abuses Remote Credential Guard to pull NTLMv1 hashes without going near LSASS or needing admin.
Shoutout to @bytewreck for the original research.
https://t.co/FfibA3bwCu
As promised, today we released DumpBrowserSecrets a tool which extracts passwords, tokens, cookies and other data from several browsers.
https://t.co/EaswGdihdU
New post: Judgment Panda - When China Spies on its "Ally" Russia
Deep dive into APT31's 3-year campaign against Russian IT contractors:
→ VtChatter: Using VirusTotal comments as C2
→ CloudyLoader: DLL sideloading + API hashing
→ IOCs, YARA rules & detection scripts
https://t.co/Lm2D2VKmTL