Forwarded from Florida๐ธ
Machine Learning Augmented Attacks
Recent threat reporting shows malicious actors are actively using AI as a force multiplier for offensive operations.
The interesting part isnโt that AI can generate code(i mean we already knew that)
The real shift is:
-Polymorphic Malware: rapid generation of variants to evade signature-based detection.
-Linguistic Smoothing: low skill actors are now bypassing "broken English" red flags in phishing.
-Condensed Attack Cycles: Reconnaissance and profiling that took days now take minutes.
๐ดFor Security & Red Teams
Focus less on what is generated,and more on how fast and how often:-
1.Content Velocity: abnormal speeds in phishing deployment.
2. LLM Wrappers: malicious use of open-source models in botnets.
3. Linguistic Patterns: Fluency โ legitimacy
4.Adaptive Payload Mutation: watch for rapid iteration patterns rather than static signatures.
AI is now part of both the exploit chain and the defense stack,the advantage wonโt belong to whoever โuses AIโ,it will belong to whoever understands how it changes execution speed.
Recent threat reporting shows malicious actors are actively using AI as a force multiplier for offensive operations.
The interesting part isnโt that AI can generate code(i mean we already knew that)
The real shift is:
-Polymorphic Malware: rapid generation of variants to evade signature-based detection.
-Linguistic Smoothing: low skill actors are now bypassing "broken English" red flags in phishing.
-Condensed Attack Cycles: Reconnaissance and profiling that took days now take minutes.
๐ดFor Security & Red Teams
Focus less on what is generated,and more on how fast and how often:-
1.Content Velocity: abnormal speeds in phishing deployment.
2. LLM Wrappers: malicious use of open-source models in botnets.
3. Linguistic Patterns: Fluency โ legitimacy
4.Adaptive Payload Mutation: watch for rapid iteration patterns rather than static signatures.
AI is now part of both the exploit chain and the defense stack,the advantage wonโt belong to whoever โuses AIโ,it will belong to whoever understands how it changes execution speed.
๐ฅ4๐2
This media is not supported in your browser
VIEW IN TELEGRAM
๐คฃ8๐ญ4๐1
Forwarded from Ge'ez Techยฎ แแแ แดแญ
#RandomThought
The Cyber sec Community here on telegram is not that active and known, so why dont we support each other and how many Enthusiast alu milewun lemasayet asbealewu so personal channel'm hone big channel sharing about cyber sec, ena if you want me to mention it here, send me your channel link @geez2012bot and i will check it ena if it looks helpful i will forward some posts from it, bezawu entewaweqalen.
tinish neger bihonm, let me support be aqme biye newu. Maqachewunm i will share some.
@geeztechgroup @geezsecurity #geeztech
The Cyber sec Community here on telegram is not that active and known, so why dont we support each other and how many Enthusiast alu milewun lemasayet asbealewu so personal channel'm hone big channel sharing about cyber sec, ena if you want me to mention it here, send me your channel link @geez2012bot and i will check it ena if it looks helpful i will forward some posts from it, bezawu entewaweqalen.
tinish neger bihonm, let me support be aqme biye newu. Maqachewunm i will share some.
@geeztechgroup @geezsecurity #geeztech
โค6
Forwarded from INSA Cyber Talent Center
แ แแแต แฒแ แ แ
แจแแ แจแ แจNathan Hailu Interview แแฌ แแณ 2:00 LT แ แแฅแณ แฅแแ แปแแ แแญ แญแ แฅแแ ๐ด LIVE TONIGHT โ 2:00 LT
Interview with Natan Hailu
Co-Founder @ GeezSecurity | HTB Certified Penetration Tester ๐
Cybersecurity โข Ethical Hacking โข Bug Hunting
๐ t.me/insactc
Donโt miss it ๐
#LiveTonight #CyberSecurity
Interview with Natan Hailu
Co-Founder @ GeezSecurity | HTB Certified Penetration Tester ๐
Cybersecurity โข Ethical Hacking โข Bug Hunting
๐ t.me/insactc
Donโt miss it ๐
#LiveTonight #CyberSecurity
๐4
okay here it goes
how many of u guys actually use c2 ? like for learning and shii may be work stuff
if u are not using it am telling u that u are missing a lotta shii there fr
i will share the matrix there are a lot of them around 170 if am not wrong which some of them are paid ( but u can find the cr4cked one hmm :)) ) and most of them are open source
@AfroSec
how many of u guys actually use c2 ? like for learning and shii may be work stuff
if u are not using it am telling u that u are missing a lotta shii there fr
i will share the matrix there are a lot of them around 170 if am not wrong which some of them are paid ( but u can find the cr4cked one hmm :)) ) and most of them are open source
@AfroSec
๐ฅฐ3โค1
AfroSec
okay here it goes how many of u guys actually use c2 ? like for learning and shii may be work stuff if u are not using it am telling u that u are missing a lotta shii there fr i will share the matrix there are a lot of them around 170 if am not wrong whichโฆ
Google Docs
C2Matrix
https://docs.google.com/spreadsheets/d/1b4mUxa6cDQuTV2BPC6aA-GR4zGZi0ooPYtBe4IgPsSc/edit?gid=0#gid=0
check them out here
@AfroSec
check them out here
@AfroSec
โก5
if u ask me why i get mad sometimes, cuz there is no real group in ethio for discussing real red team engagement and stuff like that
so far i didnt see any group, we need to move faster ๐
knowing idor or other owasp doesnt make us red teamer or knowing about what red teaming doesnt make us red teamer unless we make our hand dirty with that thing, just saying yk
what i like to say is that from now on this channel is for red team and red team only fr ๐ช
@AfroSec
so far i didnt see any group, we need to move faster ๐
knowing idor or other owasp doesnt make us red teamer or knowing about what red teaming doesnt make us red teamer unless we make our hand dirty with that thing, just saying yk
what i like to say is that from now on this channel is for red team and red team only fr ๐ช
@AfroSec
โก6โค3๐ฏ1
Soโฆ u just landed initial access on a server or compromised an org's system.
Whatโs next then ?
sudo rm -rf / ๐? Nah
u need a solid plan and decent infrastructure that guarantees persistence for as long as you want without having to re-exploit the same vuln over and over :(
Thatโs where proper infra becomes the game-changer in here .
Just running a C2 framework doesnโt magically make us anonymous or stealthy we need infrastructure OPSEC layered with serious evasion techniques and a deep plan to stay hidden through out the engagement.
In my view, we should already know exactly how to deploy and harden the full infra stack:
C2 server
Payload hosting
Phishing kit / landing pages
Redirectors (multiple layers)
Other supporting pieces
Iโve got some resources in hand so will share it to u guys,
just finished spinning up a Discord server for the discussion / sharing. Will drop the link once Iโve customized it properly (rules, channels, etc.).
so u guys down to follow along, share tips, or collab on hardening this kind of infra?
@AfroSec
Whatโs next then ?
sudo rm -rf / ๐? Nah
u need a solid plan and decent infrastructure that guarantees persistence for as long as you want without having to re-exploit the same vuln over and over :(
Thatโs where proper infra becomes the game-changer in here .
Just running a C2 framework doesnโt magically make us anonymous or stealthy we need infrastructure OPSEC layered with serious evasion techniques and a deep plan to stay hidden through out the engagement.
In my view, we should already know exactly how to deploy and harden the full infra stack:
C2 server
Payload hosting
Phishing kit / landing pages
Redirectors (multiple layers)
Other supporting pieces
Iโve got some resources in hand so will share it to u guys,
just finished spinning up a Discord server for the discussion / sharing. Will drop the link once Iโve customized it properly (rules, channels, etc.).
so u guys down to follow along, share tips, or collab on hardening this kind of infra?
@AfroSec
10๐ฅ7โก4โค2