(1/2) TL;DR "DLL sideloading attack is the most successful
attack as most EDRs fail to detect, let alone block, it." A scholarly and unbiased examination of how top EDR detects APT threats by @MDPIOpenAccess https://t.co/fotTrMbVjn
Procdump alternative that may come handy during #redteam
https://t.co/rknJPuLnbS
There is a C and a C# version that can be used with execute-assembly
❤
Finally built the proxmark3 portable and wireless. And here it goes:
RpiZeroW + PM3 + PCB with 5volt 1.5 Amp battery support + 2500 mAh Battery which lasts 8 hours @herrmann1001. Not as small as @RfidGroup though #proxmark3
https://t.co/7Uv2OJCeCr
We finally published our Outlook addin to notify suspicious mails to security teams.
It's of course linked to SwordPhish to monitor your awareness campaigns.
https://t.co/pn4neHtog5
HoleySocks, a cross-platform reverse socks proxy, now rewritten as a go package so it can be imported into other projects. Even went and used it an a reverse shell/agent.
#pivot#redteam#golang
https://t.co/VtUGmrLkuo
https://t.co/wnnQ1Jdi4g
Detect pressed keys via microphone audio capture in real-time. Uses training data captured by typing first. Very neat!
https://t.co/fIVbftye7D
Based on ideas in this classic traffic analysis paper: Timing Analysis of Keystrokes and Timing Attacks on SSH https://t.co/9r3gLRZIDg
As a #redteam, we need to be one step ahead of the blue team. Therefore, our #phishing attacks must be more sophisticated in order keep up with the game. Using #vcard, to compromise endpoints. #pentest#cobaltstrike
Active Directory forests are no longer a security boundary thanks to @tifkin_'s printer bug. Check out https://t.co/syzObbXhqt for weaponization and mitigation details and @Cyb3rWard0g's post for detection guidance https://t.co/gCLntMwSI3
A #Gmail glitch allows a hacker to send anonymous emails.
The trick could be weaponized for #phishing attacks that purport to be official warnings or system messages.
https://t.co/1RRReMYoRX