گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسی
https://t.me/+drFBtbbrVDo5NjA0
اینجا قراره ریپورتهایی که منتشر میشه رو بررسی کنیم، تکنیکهای جدید رو استخراج کنیم و دربارهی مشکلات فنی و چالشهایی که سر راه اجراست بحث کنیم.
https://t.me/+drFBtbbrVDo5NjA0
👍9👎7👾3
🔓 Dumping NTLM Hashes from Windows Memory via forensics tools
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
#RedTeam #OffensiveSecurity
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM
#RedTeam #OffensiveSecurity
👍5🔥2👾2
Forwarded from club1337
Devman-ArticleXakep.txt
17.9 KB
Вымогатель-болтун. Как Devman прошел путь от новичка до преступника в розыске Интерпола
👑 Статья для подписчиков
31 июля 2025 года Джон Ди Маджо открыл сообщение в зашифрованном мессенджере. Преступники обычно не любят, когда их деятельность расследуют, но этот написал сам. К сообщению была приложена фотография: дорогие часы, спортивные автомобили. Отправителя Ди Маджо знал.
https://xakep.ru/2026/08/13/devman/
Telegram✉️ @club1337
X (Twitter)🕊 @club31337
👑 Статья для подписчиков
31 июля 2025 года Джон Ди Маджо открыл сообщение в зашифрованном мессенджере. Преступники обычно не любят, когда их деятельность расследуют, но этот написал сам. К сообщению была приложена фотография: дорогие часы, спортивные автомобили. Отправителя Ди Маджо знал.
https://xakep.ru/2026/08/13/devman/
Telegram
X (Twitter)
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3👾2
This media is not supported in your browser
VIEW IN TELEGRAM
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
3🔥12👍4🕊2👾2
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel”, presented at DEF CON 34 and BSidesLV 2026.
#EDR #maldev #defcon
#EDR #maldev #defcon
👍6👾2
Woooowwwww
You must Read this
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
#callstack #bypass
You must Read this
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
#callstack #bypass
👾9🔥1