Sharing highlights from incident response cases in 2022 by @AymanShaaban in https://t.co/tucLfsT5JQ. You can get the slides https://t.co/gbPPvQBhWs and the analyst report https://t.co/AqDRWAY3pz #dfir#incidentresponse
This works on Windows 11 and both Gmail and MSFT will let it through to the inbox. Confirmed by @amitchell516 and @samkscholten
New detection/hunt rule is live for this, which looks for UNC paths inside URL file attachments (h/t @amitchell516!):
https://t.co/MhGRGnn20A
You still need to "train" it on the specific keyboard and you need to have sort of "ideal" conditions, but yeah -- it's a fun tool :)
Give it a try if you have a mechanical keyboard. There are examples you can run directly in your browser via WASM
I'd like to publicly introduce BinSync, a cross-decompiler collaboration tool and suite. With BinSync, you can finally share reversing data, like Types, across all your favorite decompilers (IDA, Binja, Ghidra, angr) on-the-fly. https://t.co/jjeH1VaBTi. See thread for demos.
🧵Some of my favorite LDAP queries. I let you all infer which tools to use them with. Most of these are from places around the web, nothing new. Just a list.
1. Find all DCs:
(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))
We've just published a quick write up on CVE-2023-23397, which allows a remote adversary to leak NetNTLMv2 hashes: https://t.co/xDxGwJfY2e by @domchell
New AMSI lifetime bypass, it works by searching for the first byte of each instruction to prevent updates from affecting it, Check it out.
#amsi#redteam#cybersecurity
https://t.co/J6lBOXWFyx
Zero Trust is a security strategy. It is not a product or a service, but an approach in designing and implementing the following set of security principles:
- Verify explicitly
- Use least privilege access
- Assume breach
Updated Information here: https://t.co/WVkVmGGFmT
Need an almost invisible, post-exploitation, persistent, fileless, LPE backdoor? There are many, but this one looks really beautiful for me: type "sc.exe sdset scmanager D:(A;;KA;;;WD)" from an elevated command prompt.
Check out the latest articles from the Payment Village blog https://t.co/DxyOcqAbpE :
1. How I used deepfakes to bypass security verifications in a bank.
My first experience with hacking ongoing due diligence checks using deepfake and ML.
Very cool series by @__pberba__ about persistence in Linux environments
Persistence map: https://t.co/8KaO3celxe
Auditd, Sysmon, Osquery: https://t.co/YFlzhgrWjX
Account Creation and Manipulation: https://t.co/ZbQDAbSHf3
#Linux#kernel#malware#infosec#cybersecurity
"Hello World under the microscope" - an article we wrote together with @gynvael and @j00ru! Originally published in issue 100 (1/2022) of the Programista magazine, now available online in Polish and English. https://t.co/qGCe36Wigu