I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
I haven't posted in a long time but wanted to support my region and help announce the very first Mandiant community night! Enjoy presentations from the Mandiant team and network with like minded people over food and drinks! Great opportunity! https://t.co/PflURmH8El
Watching people tweet they bypassed a certain EDR is just cringe at this point. When you ask them what did they bypass, they dont know what. So let me take you back to school...
Executing OpenSource tool is not a bypass. An EDR employs several mechanisms for detection. Getting a new implant for a twitter image is not evasion. To have a proper bypass, several conditions must be met. Lets see...
1. When you say you bypassed an EDR, what did you pass? Initial connection? Post-ex? Userland unhooking of DLLs? DLL callbacks? Exception handlers? Kernel hooks? Userland ETW or Kernel ETW? Yaras? If you didnt test any of this, how do you know that you bypassed it.
2. I know EDRs which simply allow connection and monitor it to gather more intel on threats, but will kill the implant upon interaction with local env.
3. The implant must be executed in the form of an initial access like an actual RT/TA would do.
4. All EDR functionalities must be enabled including internet for ML anomalies
5. Did you interact with the implant after getting a shell? Most EDRs will kill you on the moment of interaction with local files or processes due to call-stack scanning.
6. Does your implant leave "shouting traces" of "I exist" in memory which can be traced with a simple process monitor with a memory dump?
Most importantly, have you ever reversed the EDR or its modules to understand what exactly is happening in the back end? Do you even know "WHAT" is actually being detected by the EDR? On the other hand, I just woke up and I guess I chose voilence today. So time to go back to sleep 😂.
Come hack with us! I am hiring for operators for our Managed Red Teaming practice. This role delivers "continuous" monthly red team services for clients to a "Targeted" sophistication level, helping them mature their security program on a more frequent basis then our ad-hoc, more sophisticated advanced red team exercises, which typically last 2-3 months.
Senior candidates only, please provide a link to your GitHub and any research you have conducted. Post-Secondary education not required. There are opportunities for top performing managed red team operators to transition to the advanced team over time. US only for this req, remote.
https://t.co/2ZNFOGYy1P
Evilginx 💗 Gophish
The long-awaited official integration of Evilginx with Gophish has finally arrived with the Evilginx 3.3 update. 🪝🐟
The update includes lots of quality-of-life improvements as well.
Enjoy and happy phishing! 🤗
https://t.co/Cqma4vpRFm
Tired of failed phishing attempts?
Using the 1337est AI FAFO technology, Evilginx trained on data from thousands of successful login attempts, can now predict valid session cookies, even before the phished user starts to enter their credentials.🔥
The new era of AIshing awaits!
🚨BREAKING: Evilginx 3.2 is OUT! 🪝🐟
To celebrate the release of the new update, here is the special 10% discount code for the Evilginx Mastery course!
🎁Code: EVILGINX32 (valid until 31st Aug)
🔗Link: https://t.co/C5XxroUn7C
https://t.co/wIZx2HlxCU
Thanks to everyone who came to my DEF CON talk yesterday. I should have submitted for a 45 minute talk as I didn't have time to cover the DNS update capability of gssapi-abuse tool. DNS mode is super handy if you want to apply instant updates to AD DNS https://t.co/syW5QtTliw
@OutflankNL blog: Attacking Visual Studio for Initial Access.
The post shows how viewing source code can lead to compromise of a dev's workstation. A journey into COM, type libraries and the inner workings of VS. Plus practical examples for red team ops.
https://t.co/awZL4hiH4R