I'm exited to release GraphStrike, a project I completed during my internship at @RedSiege. Route all of your Cobalt Strike HTTPS traffic through https://t.co/u2D8xNc7db.
Tool: https://t.co/UISKwbbJYX
Dev blog: https://t.co/A1LNHqby7o
#redteam#infosec#Malware#Microsoft
The Google security team published an amazing Rust course.
I did the course few months back with almost not knowledge of C++ and 0 knowledge of Rust and loved it!
Go check it out: https://t.co/sAmLVGq58L
With a heavy ♥️ I am sad to report that a great talent/researcher/friend has passed away shortly after Thanksgiving - @Ledtech3. He was such a gift to the comm. and did some fantastic work & was always there to help when asked. The fact he was self-taught was more awesome. 1/n
This one hurts... @Ledtech3 was always my go-to any time I had some challenging code to disassemble. I always said I would have hired them in an instant if it was up to me. Such a loss for the malware research community and Infosec as a whole. You will be missed, my friend... 😔
@CareemUAE what kind of financial system are you running there? How is money from my wallet disappearing and somehow I’m the one that needs to prove the error? You have all the data you need. This is not right. Never using this crap again. #theft#ScamAlert
Sometimes instead of blogging I feel like making a big old Twitter thread, so let's talk about Cobalt Strike for people only vaguely familiar (or misinformed) with the concept. Maybe I'll blog it later.
I often get the request that a SOC would like to test their detection capabilities regarding CobaltStrike activity
I'll provide them with a solution that doesn't require CobaltStrike using some service installations, a NamedPipe creator & simulated beaconing etc.
Stay tuned
Been spending so much time in kernel mode- I didn't know that @bluefrostsec had released an exploitation challenge back in September! I used this challenge to help expand my RE and mitigation bypass skills. Full ASLR/DEP bypass on Windows 10 x64 write-up: https://t.co/L1k4qzYFGQ
i made a little CrackMe for those of you that are bored. It's a 32-bit Windows bin. You can RE it with the .pdb file if you want the easier experience. I can DM a link to the source code as well if you get fed up. Cheers! https://t.co/kxy8aVS7ZS
I've been busy in the past weeks coding on new project. Finally, here it is:
Introducing Malwarebazaar!
https://t.co/1JZycxGgir
👉 https://t.co/RJ7EHF5xhc
#sharingiscaring
#SMB#Worm??
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted compressed data packet.
Attacker can remote exploit(CVE-2020-0796) this to execute arbitrary code.
ref:
https://t.co/0Y5pxfkfVw
pdate or disable:
https://t.co/6K24i4c0mQ
Resources about network security, including: Proxy/GFW/ReverseProxy/Tunnel/VPN/Tor/I2P, and MiTM/PortKnocking/NetworkSniff/NetworkAnalysis/etc��More than 1700 open source tools for now. Post incoming. https://t.co/El1E8WSJqj