After “The Art of Evasion” @x33fcon I’m publishing NimSyscallPacker to the public. This is the most advanced public Packer/Loader I’m aware of:
https://t.co/ftd24bHryj
Recent CVE PoC & reproduction scripts. Focused on high-severity vulnerabilities across Linux kernel, Windows, macOS and more. https://t.co/2CAcx2ojyE
KslKatz: Combining KslDump and GhostKatz to dump LSASS using no-vulnerability KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-signed driver. https://t.co/pkgRtVMc2V
AV/EDR Lab Environment Setup
A curated list of various resources helpful in building own malware-centric research lab.
A post by Udayveer Singh (@m4lici0u5)
Source: https://t.co/ZM3A1n1zNQ
#redteam#blueteam#maldev#malwaredevelopment
Phantom - a project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full‑trust mode. https://t.co/GtUdD1JpCa
Raphael Mudge, the creator of Cobalt Strike, gave a free course on Red Team concepts and using Cobalt Strike a great resource for anyone working with C2.
#redteam
https://t.co/xYxuoeXOi8
Remember the team at SpecterOps open-sourced their PowerShell training, which remains a hugely relevant concept, and APTs are still actively using it.
#redteam
https://t.co/vRrlfh9mha
I am pleased to announce the publication of the sixth article in the Exploiting Reversing Series (ERS).
Titled "A Deep Dive Into Exploiting a Minifilter Driver (N-day)", this 251-page article provides a comprehensive look at a past vulnerability in a mini-filter driver:
https://t.co/Sh8pgB4bh8
It guides readers through the entire investigation process—beginning with binary diffing and moving through reverse engineering, deep analysis and proof-of-concept stages into full exploit development.
I hope this serves as a valuable resource for your research. If you enjoy the content, please feel free to share it or reach out with feedback.
Have an excellent day!
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities. https://t.co/sTpEwxtcVU