My sister was diagnosed with Breast Cancer early this year.
Iโm doing the Three Peaks to help raise funds. Any donations or shares would be REALLY appreciated! #fuckcancer https://t.co/leFzIVbBez
Introducing MalSCCM!
Today, we are releasing MalSCCM, a .NET tool by @The_Keeb which enhances PowerSCCM functionality and makes it easier to use over command and control channels.
https://t.co/InO8p0syFj
As I continue my road down token research, I thought I would document some cool findings.
Here is a writeup if you are interested!
https://t.co/v2u73IVRLX
I made a blog about research I did recently on learning COM objects internal.
https://t.co/ChtmpKjBye
I learned a lot of interesting things along the way and I'd like take it further.
Special Thanks to: @MrUn1k0d3r@waldoirc@trickster012@chiragsavla94 @KLINIX5 @tiraniddo.
Wrote my own reflective loader called KaynLdr. It uses RX Memory, direct syscalls (TartarusGate), and it erases the DOS and NT headers to make it look less suspicious in memory. Going to publish it soon.
Calling all red teamers ๐จ
Introducing RunPE. Avoid detection by running vanilla unmanaged binaries from your implant without spawning new processes. Tool and whitepaper available now!
By @m0rv4i and @benpturner. #redteam
https://t.co/RqnzmaTChC
Do you call CreateProcess() directly? Or rely on a nice wrapping function overchoice Microsoft gives us?
#ILoveWindowsAPI ๐ ๐คฏ
_execl()
_execle()
_execlp()
_execlpe()
_execv()
_execve()
_execvp()
_execvpe()
_spawnl()
_spawnle()
_spawnlp()
_spawnlpe()
_spawnv()
_spawnve()
1/3
Ever wanted to exploit that Group Policy modify access you have? Get a crash course on practical #redteam GPO client-side extension abuse in this #security#blog from @curi0usJack
https://t.co/3Hqyl84Doj
Excellent piece of "offensive" research by @FSecureLabs
That's exactly what every #redteam should research.
Your edge, as an attacker, doesn't come from a new shiny tool. It comes from knowing something the other side doesn't know that you know, ya'know?
https://t.co/fnYgLWfxP5
I started to document Win RPC interfaces & their respective methods ๐& ended up using @GHIDRA_RE for the 1st time, integrating code from @_xpn_ & @Sektor7Net research ๐ and using @ProjectJupyter notebooks & #GraphFrames ๐ to analyze the results ๐ป https://t.co/Va3ZZxMggE
Want to hone your skills ๐งโโ๏ธ๐งโโ๏ธ in time for #DC28CTF (or level up ๐ to qualify next year)?
Check out: https://t.co/TlMb4ZVl3v where you can hack on @defcon
CTF challenges from 2019 and 2020!
gr33tz to @jac_arc of the order for creating the archive!
cc @thedarktangent