I came across a simple technique that abuses Fondue.exe, a native Windows binary, to execute a custom malicious APPWIZ.cpl file placed in the same directory.
PoC and More details on how it was discovered later!
#redteam#offsec
Wow this post really blew up! If you want to know more about the smallest possible files that do things, check out the 6th annual Binary Golf Grand Prix, happening now til January 18th!
https://t.co/Lb4J5rNJGN
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
https://t.co/bmqZ9x3obQ
https://t.co/QD59sHpTEP
Would you like to be my colleague, and get to wear an awesome red hoodie? We are looking for a full-stack / offensive developer. Drop me a message or apply directly: https://t.co/GKI48eVUPC
We are giving away 1 free spot for level ZERO.
If you are a cyber pro or tech bro and want a full system reset - now is your chance.
To enter: 🔄 retweet
Bonus entry: 💬 comment below - 1 thing you want to fix in the new year.
Winner announced Friday.
#wehackhealth
Slides and Such for my @BSidesVienna talk about Linux H4x as just a bunch of syscalls, Living Under the Land on Linux
Slides: https://t.co/06QPZ6gR5G
and Such: https://t.co/6oA1XbpoAO
New writeup for #BGGP6 !!
What's the smallest Wireshark dissector? What's the most annoying Wireshark dissector?
Find out here: https://t.co/VMlMXuGXsz
Last month, @d_tranman and I gave a talk @MCTTP_Con called "COM to the Darkside" focusing on COM/DCOM cross-session and fileless lateral movement tradecraft.
Check out the slides here: https://t.co/1KNln1ldzF
Recording should be released soon.
Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ⤵️ https://t.co/mYPHg1mTKj
Red Treat was incredible. Thank you so much to @domchell@StanHacked@MarcOverIP for your hard work making another successful year. The calibre of content shared the conversations was 👌and @max__grim thanks for another swanky badge