Bring Your Own RWX Region DLL (BYORWXDLL)
New Medium post, today we are exploring a technique I call Bring Your Own RWX Region DLL, inspired by the well-known BYOVD (Bring Your Own Vulnerable Driver)
https://t.co/slNKv9qF4W
@HackingLZ@ShitSecure@0xBoku@claudeai In my personal experience, it requires some prompt adjustments first. Even with approval, it doesn't work by simply asking offensive security stuff directly.
Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion techniques against modern EDR systems https://t.co/j26UbHlFkd
I am wondering how many organizations have an effective Control Validation program?
Not considering run cases over BAS only, as BAS platforms are the tool, not the program.
Ledger - A Cobalt Strike aggressor script that tracks every operational change made during an engagement. โ Services
โ Firewall Rules
โ Accounts
โ Registry keys
https://t.co/ybXV8uNKLS
Wrote a BOF that is able to execute .NET assemblies in-memory via module stomping so ETW / AMSI are seeing a legitimate GAC assembly instead - https://t.co/IimpD8aZ66
goLoL - a Windows host scanner that finds LOLBAS binaries present on the current machine and lists techniques you can run at your current privilege level with MITRE ATT&CK mappings and example commands https://t.co/0CIRynqovI
Blog showing how AI, JavaScript browser automation, and Microsoft Graph API calls can be used to automate Entra ID tenant destruction and lockoutโs. Ransomware, but for Cloud? ๐ซฃ https://t.co/TRbHIt19en