I have always enjoyed learning through books and this one remains to be special. One of my favourites on learning RE. Got a chance to catch-up with the author @monnappa22 himself at @cysinfo22! Great meetup, once every quarter in B'lore, definitely recommend
Direct syscall detection.
A thorough description of how Cortex XDR tries to detect direct system calls.
A post by Or Chechik (@orchechik) and Ofir Ozer.
Source: https://t.co/0Q4swsMydP
#redteam#blueteam#maldev#malwaredevelopment
@mookimmegha @yash_kr_verma I saw traces of Queue-it in the responses. Tbh, was expecting them to handle the queuing themselves rather than getting another player involved (p.s no shade to queue-it)
10/10 times people who regret are those who got into CS not because they loved it
the man who loves walking will walk further than the man who loves the destination
Some of you were asking for my @x33fcon 2024 presentation.
I cover:
> current state of offsec
> why red needs to up its game to stay relevant
> entrepreneurship in the offsec world using my past experience.
Thanks #x33fcon for having me again!
Since I'm 6 drinks in for 20 bucks, let me tell you all about the story of how the first Microsoft Office 2007 vulnerability was discovered, or how it wasn't.
This was a story I was gonna save for a book but fuck it, I ain't gonna write it anyways.
I published a step by step guide on using Windows event logs to hunt for malware trying to steal sensitive data from browsers e.g. cookies, passwords etc. https://t.co/9a3l56dDJo #DFIR Hope it's useful!
One of the things I have ponderered repeatedly in life: there are folks that get bored or lonely when alone, and I have no memory of ever being bored alone after learning how to read. My memories of boredom and loneliness tend to be in the presence of people.
I've long been interested in how EDRs work under the hood and how we can apply a more evidence-based approach to evasion. I'm happy to announce that I've written a book covering these topics with @nostarch which is now available for preorder 🎉
https://t.co/tHSWnVzuMX
We've just released the first post in the Cobalt Strike reflective loader blog series! 🥷This one took allot of effort and I am excited to share it with you! The better it does, the better i'll make the next ones 😉
https://t.co/ZA2eoIwy5t
I just wrote a tutorial on how to write a Windows packer! https://t.co/Xwp7By88CA Learn to instrument CMake to help pack your executable and learn the mechanics of a fundamental piece of the chain of binary protection software!
In early 2022, Mandiant detected & responded to an incident where #APT29 successfully phished a European diplomatic entity & ultimately abused the Windows Credential Roaming feature. Read the blog post for more on this research.👇 https://t.co/nTFt9aCB9t
I knew a girl once who coded the best backdoors. She'd give them out for free, but recently she's moved to selling them. If you go to Venice Beach she has a stall near the pier. That's right. She sells C shells on the sea shore.
As a malware analyst I sometimes receive Microsoft files which have been manipulated.
E.g. infected by a virus and cleaned afterwards.
Here are some indicators to recognize PE file manipulation. 🧵
Announcement: Me and @SoumyadeepBas12 will be giving a free workshop on Offensive Lateral Movement in Windows Environment. Attached is the small glimpse of the content. You can find more details at https://t.co/0sfh8NSpo0 (1/2).