AfroSec
791 subscribers
457 photos
33 videos
7 files
239 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTO | CRTOM | CRTA | passionate about Red Teaming :)

portifolio : https://afrosec.et
blog: https://blog.afrosec.et
file : @Afr0Files
Download Telegram
Forwarded from Florida๐Ÿ›ธ
Machine Learning Augmented Attacks

Recent threat reporting shows malicious actors are actively using AI as a force multiplier for offensive operations.

The interesting part isnโ€™t that AI can generate code(i mean we already knew that)
The real shift is:
-Polymorphic Malware: rapid generation of variants to evade signature-based detection.
-Linguistic Smoothing: low skill actors are now bypassing "broken English" red flags in phishing.
-Condensed Attack Cycles: Reconnaissance and profiling that took days now take minutes.

๐Ÿ”ดFor Security & Red Teams
Focus less on what is generated,and more on how fast and how often:-
1.Content Velocity: abnormal speeds in phishing deployment.
2. LLM Wrappers: malicious use of open-source models in botnets.
3. Linguistic Patterns: Fluency โ‰  legitimacy
4.Adaptive Payload Mutation: watch for rapid iteration patterns rather than static signatures.

AI is now part of both the exploit chain and the defense stack,the advantage wonโ€™t belong to whoever โ€œuses AIโ€,it will belong to whoever understands how it changes execution speed.
๐Ÿ”ฅ4๐Ÿ‘Œ2
This media is not supported in your browser
VIEW IN TELEGRAM
the most unserious generation besmeam ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜‚

@AfroSec
๐Ÿคฃ8๐Ÿ˜ญ4๐Ÿ˜1
#RandomThought

The Cyber sec Community here on telegram is not that active and known, so why dont we support each other and how many Enthusiast alu milewun lemasayet asbealewu so personal channel'm hone big channel sharing about cyber sec, ena if you want me to mention it here, send me your channel link @geez2012bot and i will check it ena if it looks helpful i will forward some posts from it, bezawu entewaweqalen.
tinish neger bihonm, let me support be aqme biye newu. Maqachewunm i will share some.

@geeztechgroup @geezsecurity #geeztech
โค6
Forwarded from INSA Cyber Talent Center
แ‰ แŒ‰แŒ‰แ‰ต แˆฒแŒ แ‰ แ‰… แ‹จแАแ‰ แˆจแ‹‰ แ‹จNathan Hailu Interview แ‹›แˆฌ แˆ›แ‰ณ 2:00 LT แ‰ แ‰€แŒฅแ‰ณ แŠฅแ‹šแ‹‰ แ‰ปแŠ“แˆ แˆ‹แ‹ญ แ‹ญแŒ แ‰ฅแ‰แŠ• ๐Ÿ”ด LIVE TONIGHT โ€“ 2:00 LT

Interview with Natan Hailu
Co-Founder @ GeezSecurity | HTB Certified Penetration Tester ๐Ÿ”

Cybersecurity โ€ข Ethical Hacking โ€ข Bug Hunting

๐Ÿ“ t.me/insactc

Donโ€™t miss it ๐Ÿš€

#LiveTonight #CyberSecurity
๐Ÿ‘4
hellooo everyone
how u doin ๐Ÿ˜Š ?

@AfroSec
๐Ÿ˜7
aigh enough of the jokes ena malet am planing to post some advanced APT level shii from now on hmm which will strength us as a community

u ready right ??

@AfroSec
๐Ÿ‘7โšก2
okay here it goes

how many of u guys actually use c2 ? like for learning and shii may be work stuff
if u are not using it am telling u that u are missing a lotta shii there fr
i will share the matrix there are a lot of them around 170 if am not wrong which some of them are paid ( but u can find the cr4cked one hmm :)) ) and most of them are open source

@AfroSec
๐Ÿฅฐ3โค1
if u ask me why i get mad sometimes, cuz there is no real group in ethio for discussing real red team engagement and stuff like that

so far i didnt see any group, we need to move faster ๐Ÿ˜

knowing idor or other owasp doesnt make us red teamer or knowing about what red teaming doesnt make us red teamer unless we make our hand dirty with that thing, just saying yk

what i like to say is that from now on this channel is for red team and red team only fr ๐Ÿ’ช

@AfroSec
โšก6โค3๐Ÿ’ฏ1
i know am late but so sorry
EID Mubarak my Muslim friends ๐Ÿ™๐ŸŽ‰๐ŸŽ‰๐ŸŽ‰

@AfroSec
โค10๐Ÿ˜2
eth orgs dont even check their logs (especially web) enji snt gud yweta neber mtsm ๐Ÿฅ€๐Ÿฅ€๐Ÿ˜ญ๐Ÿ˜‚

but who cares, request is free right as long as we dont disrupt their business lol :)

@AfroSec
๐Ÿคฃ5๐Ÿ˜2โค1๐Ÿ‘€1
just a lil bit setup update will add some led shii soon ๐Ÿ˜‰

@AfroSec
10โšก21๐Ÿ‘2โค1๐Ÿ”ฅ1
Soโ€ฆ u just landed initial access on a server or compromised an org's system.
Whatโ€™s next then ?
sudo rm -rf / ๐Ÿ™ƒ? Nah

u need a solid plan and decent infrastructure that guarantees persistence for as long as you want without having to re-exploit the same vuln over and over :(
Thatโ€™s where proper infra becomes the game-changer in here .
Just running a C2 framework doesnโ€™t magically make us anonymous or stealthy we need infrastructure OPSEC layered with serious evasion techniques and a deep plan to stay hidden through out the engagement.
In my view, we should already know exactly how to deploy and harden the full infra stack:

C2 server
Payload hosting
Phishing kit / landing pages
Redirectors (multiple layers)
Other supporting pieces

Iโ€™ve got some resources in hand so will share it to u guys,
just finished spinning up a Discord server for the discussion / sharing. Will drop the link once Iโ€™ve customized it properly (rules, channels, etc.).
so u guys down to follow along, share tips, or collab on hardening this kind of infra?

@AfroSec
10๐Ÿ”ฅ7โšก4โค2
a sip of coffee with vibe ๐Ÿ‘Œ

@AfroSec
โค12๐Ÿ‘1
aigh fam

lets see email security in a nutshell
topic sounds lame but absolute masterpiece

why do you think some emails go to spam folder also why does those emails flagged by email-gateways ??

@AfroSec
โšก3
so there are 3 DNS records which have impact on email sec
> SPF
> DKIM
> DMARC
lets see each one of them

SPF:- Sender Policy Framework
> lists which servers are allowed to send email for your domain
> for instance example.com's SPF record says like :"only 192.168.x.x can send an email as @example.com"

DKIM:- DomainKeys Identified Mail
> when you send an email, your server stamps it with a unique, invisible signature. when the receiving server gets it, they check that signature against your domainโ€™s public key, if your mail lack this one it will get rejected entirely or flagged as spam

DMARC:- Domain-based Message Authentication, Reporting & Conformance
> simply Tells receiving servers what to do with emails that fail SPF/DKIM checks


so from our RedTeam perspective we will check those records which is kinda passive recon thing,
then if the server miss one of those like
1, No SPF rec
2, SPF and DKIM but No DMARC
3, No SPF and No DMARC


those are our jackpots kinda a way in ;), how ?

social engineering comes to play here
we can send an email as example.com for that example.com employee which have initial access payload either it could be macros, Dll side loading or anykinda thing that u prepare for ur foothold

the main and good thing is email gateways and browsers wont flag for MOTW that attachment why because we just send that email as internal email with trusted domain :)) lucky us huh ?


if u ask me what MOTW is here is the post i wrote abt it > https://t.me/AfroSec/765

@AfroSec
5โšก5