As it turns out, local #LLMs have a few opinions about large workflows 🤖 In our latest blog, Senior Research Analyst @kev169 walks through the scaling challenges of local LLMs and the custom #Python library he built to wrangle them. Read it now! https://t.co/dXufhlEvMh
What started as a basic scanner project evolved into a comprehensive endeavor.
In our latest post, Kevin Hubris reflects on XZ Utils backdoor news, exploring detection methods pre and post-upgrades. Read it now! https://t.co/AANBY9hfMp
#Security#Blog
🚨 Today we're excited to release Ghidrathon, a Ghidra extension that adds modern Python 3 scripting (including Python 3.10) to Ghidra!
Blog 👉 https://t.co/oA1aY813R0
GitHub 👉 https://t.co/8wy30NmNoN
Find out how building memory loaders can allow you to simulate BOFs for Linux and Mac using new Cobalt Strikes BOF internal functions in our newest #security#blog
https://t.co/E6Fa9ykF07
@HackingLZ Best part is that with this loader the object files (built for linux) run on Linux, mac, and anything else that uses the same calling conventions. :)
The research team @TrustedSec is happy to announce we're releasing some of our previously internal bof's. Most of it is using windows API's for primitives that can build up to larger actions. If that interests you see more here https://t.co/VW7BZqmWar
My colleague @gijs_h posted an awesome blog on converting BOFs to shellcode, which enables you to use them with other/custom C2s.
Shoutout to @TrustedSec for the COFFLoader.
https://t.co/7exsNqC6t1
#FalconForce#RedTeam#Shellcode
Join Senior Research Analyst Kevin Haubris in making memories in “COFFLoader: Building your own in-memory loader or how to run BOFs” by following his process breakdown ✨#blog
https://t.co/szZk4NJ56c
Join @Carlos_Perez and Christopher Paschen for our next #webinar, "Using #Research to Gain Attack Intelligence," on Wednesday, November 4 at 1pm Eastern. Register now to get a glimpse into some of TrustedSec’s internal, proprietary tooling.
https://t.co/RRLfKRKRfR
Cobalt Strike 4.1 allows code to be run in a more #OPSEC friendly manner. Senior Research Analyst Christopher Paschen outlines less obvious restrictions of Beacon Object Files and shares his #workflow to assist anyone tasked with writing in this format!
https://t.co/EgoBiTZuB7
@jaredhaight @brysonbort@Carlos_Perez So more of the steps from "I've identified a need for a custom tool" through to "Stable tool developed and ready for use" just using a agent and C2 as an example.
#TrustedSec is expanding its training with online, public offerings! @HackingDave shares how these instructor-led courses will help further educate our #InformationSecurity community and industry #TrainingTuesday
https://t.co/leg2iKRVRN
@MagisterQuis That, and if it’s in c or c++ the valgrind output, if I see tons of errors or memory leaks I’ll just write it from scratch, easier than fixing.
Hey @ATTHelp - *PLEASE* consider raising the 100GB data cap on rural workers using wireless LTE hotspots (no fixed wireless here). We could use a break right about now...
Get yourself a job / gig at some point in your career where you have no access to Google - sone facility with no phones or internet allowed or accessible for one reason or another. You will be stretched in ways you didn’t think possible and read man pages you’ve only skimmed.
Senior Research Analyst Kevin Haubris is discussing #SELinux (Security-Enhanced Linux) and Auditd in our latest #blog Find out how to use them, how to determine what the default policies are doing, and how to add new ones!
https://t.co/o57mkIIKFP