For anyone that's interested, following my talk 'Immoral Fiber: Unlocking & Discovering New Offensive Capabilities of Fibers' at Black Hat Asia 2024 #BlackHat I have open-sourced my new techniques here:
https://t.co/0vESTgXPOt
Here's our new blog on hiding your implant in VTL1, where even an EDR's kernel sensor can't see it.🧑🦯
Post includes full operational details. Plus our OST offering has been updated with a Cobalt Strike sleep mask exploiting secure enclaves.
Full read ➡️ https://t.co/oe9A6RowDV
Thread Execution Hijacking is one of the well-known methods that can be used to run implanted code.
In this blog we introduce a new injection method, that is based on this classic technique, but much stealthier - Waiting Thread Hijacking.
Read More : https://t.co/ptdomYaAZG
🚀 New Blog & PoC: Abusing IDispatch for COM Object Access & PPL Injection
Leveraging STDFONT via IDispatch to inject into PPL processes & access LSASS. Inspired by James Forshaw's research!
🔍 Blog: https://t.co/TKdtwuj509
💻 Code: https://t.co/tlppakaLPO
Bypass AMSI in 2025, my newest blog post is published 🥳! A review on what changed over the last years and what's still efficient today.
https://t.co/hSqMxeJx2K
I created a hypervisor-based emulator for Windows x64 binaries. This project uses Windows Hypervisor Platform to build a virtualized user-mode environment, allowing syscalls and memory accesses to be logged or intercepted. https://t.co/KbsWfdLT3D
Project:
https://t.co/xJvm24qqXv
[BLOG]
This post summarises how to tie Cobalt Strike's UDRL, SleepMask, and BeaconGate together for your syscall and call stack spoofing needs.
https://t.co/7wTF0zqgPP
Virus Bulletin (VB) just released my talk & white paper on Shared Object injection & detection on Linux.
Pleasure to be invited & attend. Great conference guys! @virusbtn#VB#VirusBulletin#Linux
https://t.co/TzlJgIx1V4
https://t.co/nP5zWsMNIv
obfus.h is the powerfull compile-time obfuscator for C (win32/64). Supports virtualization, anti-debugging, control flow obfuscation and other code mutation techniques to prevent disassembly or decompilation.
#CodeSecurity#Obfuscation#infosec
https://t.co/i6dnpRJUAF
Excited to share my latest blog post: "Breaking Control Flow Flattening: A Deep Technical Analysis"
I showcase usage of formal proofs and graph theory to automate CFF deobfuscation, among other things !
Might make it a talk...? 👀
https://t.co/iWoP9GeZhX
My talk from earlier in the year @BlackHatEvents#BlackHatAsia just got posted.
Immoral Fiber: Unlocking & Discovering New Offensive Capabilities of Fibers https://t.co/AMe3aGD4zQ
At #VB2024@JanielDary will dig into techniques used to maliciously load Shared Objects & describe ways to detect them. He'll present a tool that identifies SO injection, shellcode injection, process hollowing &entry point manipulation of running processes https://t.co/hznsAn2AAQ