This will be a thread discussing a real world breach involving a drone delivered exploit system that occurred this summer
Some details I am not able to discuss, however for the blue teams & red teams out there I hope this provides a good measure of capability.
🧵🚁 🎮🖥️🦠
For over a year, EasyAntiCheat's virtual machine code to asses kernel driver integrity was vulnerable to attacks abusing call hierarchy (the hierarchy of which functions are executed during integrity)
Full write-up here: https://t.co/qjFruMuu6R
Ilya Lichtenstein and his wife, Heather Rhiannon Morgan, laundered 119,745BTC ($4,500,000,000) from a crypto exchange breach which occured in 2016. They were arrested today.
Heather Morgan was a @Forbes contributor and rapper. This is her music video.
https://t.co/H3GdnnKCtS
@thepoolshark Missed opportunity to name it the Liability Award :) Also, kind of hope Trip gets it so he has to look at all those stars and stripes LUL
[Tooling ⚔️] Updated DInjector with the 'CurrentThreadUuid' technique (based on a blog post by Sunggwan Choi): shellcode in a list of UUID strings ➡️ HeapCreate & UuidFromStringA to convert and copy the SC ➡️ EnumSystemLocalesA to trigger the callback 🔥 https://t.co/lAGFzjFNj7
Been a few months in development on and off, but finally got an end to end POC working for lsarelayx. System wide NTLM relay from Windows which relays all incoming NTLM authentications without affecting the original target application. Silent relay if you will.
🧠 Mental models are useful for developing solutions and stimulating thinking. In this post, I discuss some personal mental models I've found useful for offensive capability R&D, which can also generalize to understanding opponent processes in InfoSec.
https://t.co/anpVQqIpcV
Manage resource-based constrained delegation using impacket. Enables abusing PetitPotam/ntlmrelayx to compromise non-dc host when SMB signing is enabled:
petitpotam->ntlmrelayx->adcs->cert->rubeus->tgt->delegateAccess.py->getSt.py->PWN
https://t.co/IszvdzYZg9
New version of Reflective Loader that checks beacon process to see if DLL's are already loaded to limit callbacks from LoadLibrary API. Also custom getSymbolAddress function written in assembly to reduce hits to GetProcAddress API... And code refactor!
https://t.co/Q7XsJfizdz
A sneak peek of #Sysmon for Linux 💥
Thank you @kevsecurity for your hard work and for sharing your research @eBPFsummit ! #ebpf#eBPFSummit
🚨 Release scheduled for early October 2021 🚨
Looking forward to it 🍻 #MSTIC R&D team 😎
It was the most time consuming #ThreatIntel report in my career😤
#REvil TTPs hunting campaign is finished:
- 37 detection ideas
- 81 detection rules (Windows/Sysmon/EDR)
plus BloodHound & BITS jobs:
https://t.co/GoDYfvaFJF
Excellent work @TheDFIRReport team!
#threathunting
So, this is awkward, It's not you, it's us. We're still in our PJs, quarantine hair, kinda preferring it that way.
We're gonna tar.gz the con into one day, virtual, Nov 6th. The CFP will open Sept 1.
Watch https://t.co/480fl2rRKi for detail^H^HWARNING! InComIng GAmE CuBe