.NET malware analysis tip: If you see "This breakpoint will not currently be hit" for a dynamically invoked method:
Wait for the assembly to load (e.g., [System.Reflection.Assembly]::Load(byte[] assembly)).
In dnSpy:
- Go to View > Options and enable "Debug files loaded from the process' memory."
- Then, in Debug > Windows > Modules, right-click the malicious assembly, select "Go To Module", and now try to set the breakpoint.
#MalwareAnalysis #dnSpy #ReverseEngineering
@BendidiWissal I live not far from there haha, when i was unemployed my routine was to work 5-6 hour in some coffee near by the metro station then i used to go watch movie at mk2.
🚨 Top 5 Underrated Tools Every Bug Bounty Hunter Should Try in 2024 🚨
1. Fuzzapi - Unleash the beast on API security testing!
2. GitGot - Sniff out sensitive leaks in public repos like a pro.
3. PwnFox - Turn your browser into a red team machine.
4. Sn1per - Automate your recon like never before!
5. ShodanSploit - The Google for hackers, upgraded!
#EthicalHacking #BugBounty #CyberSecurityTools #InfoSec
@BendidiWissal But still, i love the creativity this field bring into us and how our idea may shift the reality and out perception of IT. And it's hard to make it concrete when you work in a company.
@BendidiWissal Depending on the person pov tbh، like you can work a 9 to 5 job and get really well paid, and it's enough for you. Or you get ambitious and believe in youself to carry out grander project. In IT, the debut is easy but then you have to market it and get your first customers.
Yesterday I became acquainted with a young and passionate person who, for the past 2 years, has been documenting RATs (images, versions, port usage), and ransomware payloads (images, notes, contact information).
They've documented 92 ransomware variants including (if applicable), their manuals, builders, etc.
They've documented 474 RATs variants including (if applicable), their version history, builders, source code, manuals, etc.
When I spoke with them they shared they've discovered (through various means) hundreds, possibly thousands, of other malware builders from various countries dating back nearly 2 decades. They've been slowly reviewing them all and documenting them by themselves.
Interestingly, as our staff is limited on resources, having family issues, or having new family members introduced, we suddenly discovered a young and passionate person who has been working tirelessly for 2 years without much recognition.
When one door closes, another door opens.
Chat, we may have a new staff member
VXUG 🤝Cryakl
🚨 Zero-Click Vulnerability Alert: Microsoft patched a critical zero-click RCE vulnerability in Windows OLE (CVE-2025-21298).
9.8 on CVSS and allows attackers to exploit systems with no user interaction. - Just previewing an email.
Let’s break it down 🧵👇