Top Tweets for #RedTeamTip
#redteamtip: This is one of the quickest wins you can have in a Red team. During my last engagement, I found an active notepad process, but was not able to access its network path as the location of the text file was unmounted. However, since the process was active, I checked the status of the process using 'psgrep' and 'windowlist' command of Brute Ratel.
The 'windowlist' command does show the path of the share at times.
Next, I dumped the notepad memory and extracted the dump in a fileless manner.
Finally, used strings and grep on the dump file offline to search for the user's name and its adjacent strings.
Make note that notepad.exe/office etc. stores the buffer of the process in UNICODE. Thus you have to use 'strings --encoding=l' to search UNICODE strings and then use grep without casing (-ie). In my case I searched for the user's name with -A (after text) and -B (before text) to search for adjacent lines of text which might contain password. Remember that LSASS is not the only thing that stores passwords π, and you might not get all sensitives files just by searching for files, as some might only exist in memory π€.

#redteamtip: During my last 4 redteams in the past 1 year, I haven't spawned a full HTTP payload. I would rather spawn a http connector which checks in at specified interval and connects to a badger in another process via local named pipe. This way, my core badger and my http connector run seperately. My named pipe is only connected when the sleep interval is over. Thus even if the blue team hunts down and starts analyzing my http payload, they wont find my payload core. The payload core is also configured in such a way that if it doesnt find the http connector's PID running, it will simply exit to avoid further IOCs. Creativity is the limit here. Havent found a single EDR or blue team detect this till date π€.
#redteamtip: In linux you can simply exfiltrate the '.mozilla' or the 'snap/chromium' dir from the home and restore the full sessions/profiles/passwords on your own computer. Compromised an entire dev env in a red team by just exploiting one ssh key and chromium of a dev. π€
#redteamtip Need to duplicate or forge a form or corporate document but don't have have access to a original? A lot of people use the website https://t.co/ObyIX8QDbh to fill out documents online and the documents they upload to the site are searchable and downloadable
#redteamtip don't get caught
RedteamTip:
If you compromise an account member of the group Backup Operators you can become the Domain Admin without RDP or WinRM on the Domain Controller.
Just by using BackupOperatorToDA.exe tool
CC: @mpgn_x64
#redteamtip
https://t.co/r9FChPcT7p
@vxunderground That's s common misconception about the RPG-7. #RedTeamTip you don't need to enter a facility with it, just use enough ammo to bring down the walls until you reach the room where the EDR is running
Recently we have received criticism for our #1 #RedTeamTip of using an RPG-7 to bypass EDRs. Some individuals pointed out an RPG-7 would not be allowed on most corporate premises.
While this may be true, vx-underground also has a 0day exploit to get access to ANY facility.

We have seen many tweets recently about silly malware concepts like "syscalls", "unhooking", or "obfuscation".
Here is our #1 #RedTeamTip to avoid EDRs. Use an RPG-7 to obliterate the computer. The EDR cannot detect your malware if the computer is not operational

Hey #Hackers! We will be hosting a stream with @NahamSec @_johnhammond @thecybermentor @stokfredrik talking about our CTF and events during #defcon. We will be giving out a ton of prizes, but I need your help. Do you have a #RedTeamTip that you want to share? #CyberSecurity
Using Google's OpenRedirect to Bypass Mail Filters for Phishing
h[xx]ps://googleweblight.com/i?u=https://www.redteam.cafe
#RedTeamTip #RedTeam
Since @vysecurity told me to post some tips, here is one of my golden tip. RedTip # 407 Not a lot of people know about Find-DomainPropertyObjectOutlier in Powerview. Use it to find hidden secrets inside AD Attributes.
#RedTeam #RedTeamTip
πGreat feature of WMI is dat it allows us 2 subscribe 2 specific system events like process starts by subscribing 2 event notifications from WMI providers such as WIN32_process. Subscribing to an occurring system event is a gud way 2 maintain fileless persistence #redteamtipπ
Outlook wil block email with malwares attached BUT You can use 'Microsoft Teams' to send Malwares
also you can use teams to send almost every file type, .zip, .exe, .vbs, .ps1, .hta, .lnk
@MicrosoftTeams @msftsecresponse
#RedTeamTip
#MicrosoftTeams
#Microsoft
#CyberSecurity
you can get network & other informations by executing windows default file: C:\Windows\System32\gatherNetworkInfo.vbs
#redteamtip
#redteamtip If you bought a phishing domain which resembles the real domain closely, setup a catch-all mailbox to get all the mails people sent to the phishing domain by mistake. Absolutely goldmine!
Tattoo all your scored krbtgt hashes as a chest piece to attract new clients. Shows #dedication which customers love. #prestige #redteamtip
Last Seen Hashtags on Sotwe
SoloBrathukeSoBetterReview
Seen from United States
LauzHackAgainstCOVID19
Seen from United States
gloryhole
Seen from United States
prelemi pierpaolo
Seen from Italy
Puke
Seen from France
WASMO
mayamax
Seen from Italy
british #tits
Seen from Japan
anxiouspanda()()()()**filter:native_video()**filter:native_video()**filter:native_video()**filter:native_video
Seen from Germany
minichat
Seen from Mexico
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
241.5M followers

Barack Obama 
@barackobama
118.9M followers

Cristiano Ronaldo 
@cristiano
114.6M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.1M followers

Rihanna 
@rihanna
98.7M followers

NASA 
@nasa
92.3M followers

Justin Bieber 
@justinbieber
91.8M followers

KATY PERRY 
@katyperry
90M followers

Taylor Swift 
@taylorswift13
84M followers

Lady Gaga 
@ladygaga
75.5M followers

Virat Kohli 
@imvkohli
73.5M followers

Kim Kardashian 
@kimkardashian
70.9M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
66.5M followers

Bill Gates 
@billgates
65.2M followers

Selena Gomez 
@selenagomez
63.1M followers

The Ellen Show
@theellenshow
62.2M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers



















