#DFIR Pros, noobs, and #infosec junkies - the final walkthrough necessary to answer all of the big questions surrounding the case of the stolen Szechuan Sauce is complete! Learn how to enrich disk image timelines with events pulled from the memory image!
https://t.co/bBZ6NhEt2W
Today: On an endpoint with the most well-known EDR. NtdsAudit.exe blocked. Renamed to pentest.exe, echo 0 >> pentest.exe, pulled back down. No more blocking or alerts.
I guess they haven't seen: https://t.co/JATAclJcfm
Bonus: reversible encryption for the win.
RedMimicry
Actor Emulation and Breach Simulation Tool
by @ReleasePreview
- a great example of how to do it right
- vetting
- watermarked
- YARA and Sigma rules
https://t.co/Yb6kgEUGct
An Italian hospital ran out of ICU valves. A local biz brought a 3D printer to the hospital, redesigned & produced the valves in a few hours.
“At the time of writing, 10 patients are accompanied in breathing by a machine that uses a 3D printed valve.”
https://t.co/HjjdYKZvyS
My first blog post! Bypassing AV via in-memory PE execution. I've created a tool to go along with the post and help automate creating undetected PEs, links inside the post 😉 https://t.co/YOhj5XaKtA
Magic Unicorn 3.8.1 released.
Adds new method for platform detection, obfuscation, and a fix for python2 raw_input when using AMSI bypass.
https://t.co/YeXwYojd5l
#TrustedSec
Minjector & Memhunter: learning code injection techniques and hunting memory resident malware like a boss (aka at scale) by my friend and @McAfee colleague @marcosd4h - https://t.co/PhIKQMjI9T #DFIR#ThreatHunting