Sec Note
2.88K subscribers
140 photos
9 videos
51 files
233 links
Download Telegram
Forwarded from club1337
Devman-ArticleXakep.txt
17.9 KB
Вымогатель-болтун. Как Devman прошел путь от новичка до преступника в розыске Интерпола

👑 Статья для подписчиков

31 июля 2025 года Джон Ди Маджо открыл сообщение в зашифрованном мессенджере. Преступники обычно не любят, когда их деятельность расследуют, но этот написал сам. К сообщению была приложена фотография: дорогие часы, спортивные автомобили. Отправителя Ди Маджо знал.

https://xakep.ru/2026/08/13/devman/

Telegram ✉️ @club1337
X (Twitter) 🕊 @club31337
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3👾2
This media is not supported in your browser
VIEW IN TELEGRAM
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.

As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.

So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?

If the goal is to obtain local account credential material, SAM might be enough for what we need.

The point is simple: choose the technique based on the objective, not based on how complicated it is.

#EDR #SentinelOne
3🔥12👍4🕊2👾2
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel”, presented at DEF CON 34 and BSidesLV 2026.

#EDR #maldev #defcon
👍6👾2
😁21
Forwarded from RedTeam brazzers (Миша)
Всем привет! Мой коллега Вячеслав Цепенников выступал на OFFZONE с докладом «Living off the Browser». Он наресерчил крутой функционал Direct Sockets внутри Chrome, который позволяет через Isolated Web Apps отправлять полноценные сетевые TCP/UDP-запросы. Путем нескольких бессонных ночей получилось внутрь Isolated Web App портировать большинство самых популярных тулз для пентеста! Теперь вы можете буквально ломать через браузер : )

Демо:
https://iwa-tools.pkilla.pw/
Сорцы:
https://github.com/CICADA8-Research/iwa-tools
👍3🔥3
🔥 HTB PingPong — Insane | Pwned

Started from the assumed-breach credentials.

Attack Chain:
→ "ESC13"
→ "WinRM Foothold on DC1"
→ "Hyper-V Pivot"
→ "Cross-Forest / Cross-Realm Kerberos"
→ "RID Enumeration"
→ "gMSA Managers Ownership"
→ "Foreign SID Injection"
→ "Read Pong_gMSA$ Password"
→ "JEA → XXE File Read"
→ "RBCD → MSSQL"
→ "GodPotato"
→ "Local Admin on DC2"
→ "DCSync → R.Martinelli"
→ "CA Managers"
→ "ESC4 → ESC1"
→ "PKINIT as Administrator"
→ Domain Admin


ESC13 provided the initial WinRM foothold. A Hyper-V pivot exposed the second forest and enabled cross-realm Kerberos.

Abusing gMSA Managers and Foreign SID Injection allowed access to the "Pong_gMSA$" password, leading to JEA abuse and an XXE file read.

From there, RBCD against MSSQL → GodPotato resulted in local admin on DC2. DCSync then compromised "R.Martinelli", providing access to CA Managers.

Finally, ESC4 → ESC1 → PKINIT yielded an Administrator certificate and Domain Admin.

One hell of an AD chain. 🏴‍☠️

#AD #HTB
🔥12👾3👍2
Forwarded from Seclog
🔥7👍2
This media is not supported in your browser
VIEW IN TELEGRAM
Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools

A reverse-engineering teardown of SentinelOne Agent 26.1.2.177. The alarming part isn’t any single detection rule it’s how little skill, and how little time, it took to pull the whole detection stack apart on a workbench.

#Edr
🔥5👍3
Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)


A trusted user-mode client can become the path through which an attacker reaches a privileged Windows driver.
👾5👍2
👾6🕊2
Forwarded from cKure
■■■■□ Anduril Military Equipment hijacked by Iran.

🇺🇸🇮🇷 Iran announces it monitored, ambushed, and captured the most advanced and classified American Unmanned Underwater Vessel in the Strait of Hormuz

The unmanned submarine contains the most advanced and new technology, and was only delivered to the U.S. Navy a year ago, in 2025.

It has been captured in a complete state, and will be showcased on state TV in the coming hours.
🔥10👍1👎1🕊1