Top Tweets for #LOFLCAB
#LOFLCAB highlight: reg.exe
Persistence in registry or reconnaissance, e.g. listing recent mstsc.exe connections: "\\W10\HKEY_USERS\S-1-5-...\Software\Microsoft\Terminal Server Client\Servers"
๐ Details: https://t.co/cvAo2fpHcH
๐ Full quality video: https://t.co/SU8SBGT9lU
Excited to finally publish research which in the background I have been working on for several years!๐
Introducing Living Off the FOREIGN Land (#LOFL), using a Windows VM over SOCKS as offensive platformโจ
๐ https://t.co/X3vUyWDLXM
๐ https://t.co/7yQqQCp6V9
More info โฌ๏ธ

#LOFLCAB highlight: New-NetEventSession cmdlet
Using Event Tracing for Windows (ETW) for offensive purposes: Sniff network traffic on a remote machine without installing additional tooling ๐ฅ
๐ Details: https://t.co/3hxDa396js
๐ Full quality video: https://t.co/lxHHKomYox
Excited to finally publish research which in the background I have been working on for several years!๐
Introducing Living Off the FOREIGN Land (#LOFL), using a Windows VM over SOCKS as offensive platformโจ
๐ https://t.co/X3vUyWDLXM
๐ https://t.co/7yQqQCp6V9
More info โฌ๏ธ

#LOFLCAB highlight: Ssms.exe
Using SQL Server Management Studio with Kerberos authentication to obtain command execution on the SQL server using the xp_cmdshell stored procedure.
๐ Details
https://t.co/JmBsFq2h0c
๐ Full quality video
https://t.co/9Gfgsgp0Mk
Excited to finally publish research which in the background I have been working on for several years!๐
Introducing Living Off the FOREIGN Land (#LOFL), using a Windows VM over SOCKS as offensive platformโจ
๐ https://t.co/X3vUyWDLXM
๐ https://t.co/7yQqQCp6V9
More info โฌ๏ธ

New #LOFLCAB added to LOFL-Project website!๐ค
WMI class: Win32_Product
Can be used to have a remote Windows machine download and install a (malicious) .msi installer package from a URL.
Details: https://t.co/ElaF4oqsaG
Full quality video available at https://t.co/HJO6TRRxAP
Excited to finally publish research which in the background I have been working on for several years!๐
Introducing Living Off the FOREIGN Land (#LOFL), using a Windows VM over SOCKS as offensive platformโจ
๐ https://t.co/X3vUyWDLXM
๐ https://t.co/7yQqQCp6V9
More info โฌ๏ธ

๐ฎ2/4
Using a compromised endpoint for only routing of (SOCKS) traffic keeps away malicious activities from the endpoint, limiting defender visibility. Numerous built-in Windows #LOFLCAB can be used for offensive activities performed from the attacker's Windows VM.
Last Seen Hashtags on Sotwe
sexwife #cuckold
Seen from Thailand
March8
Seen from United States
CrossBorderTrade
Seen from United States
anxiouspanda() ** () filter:videos
Seen from Austria
pathan girls
Seen from United Arab Emirates
ุณูุณ_ู
ุฏููุน
Seen from Netherlands
cuckoldรงiftler
Seen from Turkey
ูุถูุญุฉ_17_ุฏูุณู
ุจุฑ
DIANITA_1988
Seen from Saudi Arabia
kayseripasif
Seen from Turkey
Most Popular Users

Elon Musk 
@elonmusk
241.7M followers

Barack Obama 
@barackobama
119M followers

Cristiano Ronaldo 
@cristiano
114.5M followers

Donald J. Trump 
@realdonaldtrump
111.9M followers

Narendra Modi 
@narendramodi
107.2M followers

Rihanna 
@rihanna
98.7M followers

NASA 
@nasa
92.4M followers

Justin Bieber 
@justinbieber
91.8M followers

KATY PERRY 
@katyperry
90M followers

Taylor Swift 
@taylorswift13
84M followers

Lady Gaga 
@ladygaga
75.5M followers

Virat Kohli 
@imvkohli
73.5M followers

Kim Kardashian 
@kimkardashian
70.9M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
66.5M followers

Bill Gates 
@billgates
65.2M followers

Selena Gomez 
@selenagomez
63.1M followers

The Ellen Show
@theellenshow
62.3M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers
