Sec Note
2.19K subscribers
124 photos
6 videos
48 files
209 links
Download Telegram
👾4
Good write-up on building a kernel-based EDR and understanding how Windows telemetry is actually implemented.

Focus is on real detection primitives like:
PsSetCreateProcessNotifyRoutine(Ex) for process lifecycle monitoring

PsSetLoadImageNotifyRoutine for image/DLL tracking

ObRegisterCallbacks for process/thread handle filtering

kernel → user-mode communication via IOCTL + agent design

https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
👾2
TL;DR: Two command injection vulnerabilities exist in the Windows Explorer “Open PowerShell window here” context menu due to improper quoting and command injection through user-controlled folder paths. By creating folders with crafted names (e.g., folder; calc), an attacker can trigger arbitrary PowerShell command execution when a user uses Shift + Right-Click → Open PowerShell window here. One variant affects modern Windows 11 builds, while another existed since Windows 10 1703 (2017).


You can find the scenarios and the slides of the Insomni’hack 2026 talk in https://github.com/p0dalirius/Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus
👍2
Malware, Cats and Cryptography
2026-cocomelonc-bsideslux.pdf
Let me keep it short… use uncommon stuff for static

(here is my conference ┐⁠(⁠ ⁠∵⁠ ⁠)⁠┌)
chain things smart to get past behavior detection.
SentinelInstaller_windows_64bit_v25_1_4_434.msi
57.9 MB
Token:
eyJ1cmwiOiAiaHR0cHM6Ly9ldWNlMS0xMDkuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogImNkZWIxMGEwYmM4ZGUwMTU3ZjliZGRmNjdkMDJmOTE2NzE0NjMwNzEyNGIxNTlhYzcwZGRmYWI2OGZiYzEzNGEifQ==

#EDR
1👾5🔥3
Forwarded from Life-Hack - Хакер
OPSEC-провалы

#opsec #полезное #redteam

Подборка случаев, от неприятных ошибок до громких провалов, заканчивавшихся утечками данных, деанонимизацией и раскрытием целых групп. Внутри статьи, видео и материалы судов. Полезно для изучения, чтобы не наступить на те же грабли и понять, где искать зацепки в своих расследованиях.

Ссылка на GitHub

LH | News | OSINT | AI
👍3
Adversarial Tradecraft:
Interactive slide deck covering operational security principles for authorized red team operations and penetration testing engagements.

Live site: hackinglz.github.io/tradecraft-training Repo: github.com/HackingLZ/tradecraft-training
👾5
Bring Your Own RWX Region DLL (BYORWXDLL)

There are a lot of places in OneDrive and .NET stuff, also browsers but they have some protection...
👾6🔥5
Forwarded from Order of Six Angles
🔥6
Soheil Hashemi's Certified Azure Red Team Expert (CARTE) Review
A look at his journey to earning the CARTE certification.
https://www.soheilsec.com/certified-azure-red-team-expert-carte-review/
🔥12👍3