After 3 years, I just shipped Mergen v2 🛡️
Open-source macOS security audit tool. 85 CIS Benchmark checks, auto-fix, native SwiftUI app + Go CLI.
It doesn't just tell you your firewall is off. It turns it on this time.🔥
https://t.co/EUZgsx1QIJ
Call stack analysis is very popular these days. Another API that can be used for clean call stack in API calls and system calls is TrySubmitThreadpoolCallback/TpSimpleTryPost. Here is the PoC for proxying DLL loads: https://t.co/sHVIbHgF2u
@dobinrutis I watched your presentation on Youtube, cool presentation and research. 👍 Also, active usage of RefleXXion in the field made me happy, thanks. 👊
Here is the RefleXXion. It is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc.
https://t.co/gEihB7ZQHY
Thank you @peterwintrsmith for sharing this technique.
@C5pider@0xCrashX 4/4 If you still insist on using a mod that will require you to mess with Padding, as far as I can see you are using Tiny-AES-C, I recommend reading this content. https://t.co/mUOvbMQ7Iw
@C5pider@0xCrashX 3/4 For the CS way, I have two suggestions, it might be good for a little improvement.
1- If I'm not mistaken, the Beacon uses a fixed value for the IV value. You can randomize this.
2- You can use AES 256-Bit CTR mode. That way you don't have to deal with goddamn padding. :D
@C5pider@0xCrashX You can do the key exchange just like Cobalt Strike did. I had done a similar integration for myself before, with a little improvement.
“A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.”
Is there a better project description than this? I haven't seen it yet. 😅👌
https://t.co/T6SrLbkDsg