Following up on UNCanny, I found out that you can leak the host’s NetNTLM from a Windows Sandbox .wsb file by pointing HostFolder to a UNC path, before the sandbox even finishes starting. Funny place for a credential leak to hide 👀 Read more: https://t.co/fEi1VHmkrt
#redteam #intialaccess
I published a small repo for some fresh windows execution-path hunting, covering a BOF for the undocumented Shell.HWEventHandlerShellExecute AutoPlay COM handler flow for execution, also with other notes on ssh-shellhost.exe as a new PTY-based execution LOLBin-ish path. Read more: https://t.co/WBpYNTPe4I #redteam
New research disclosed
فريق Dexpose و Darkatlas
قدرنا نعمل identity reveal ل Quellostanco
عضو في Int3x
اللي كان بيتارجت الجامعات والحكومات المصرية
We successfully conducted a full identity reveal on Quellostanco, an active member of the Int3x group, who was systematically targeting Egyptian universities and government entities.
https://t.co/FR45Q1jIOC
المشكلة الازلية في الشعب دا ان أغلبه ماشي بمبدأ ابو بلاش كتر منه
ممكن كتير منهم مش محتاج كمية التمر دي هو يكفيه ٣ او ٥ تمرات بالكتير بس بيستخسرو يلاقو حاجه ببلاش و مياخدوش منها اكبر كمية ممكنه
انا بكره الفئة دي من الناس فشخ لأن للأسف بتبقى هي دي ال prototype عند ��لناس عن مصر