“Insider Threats in the Remote Work Era Challenges and Solutions”
The shift to remote work has revolutionized the modern workplace, providing flexibility and efficiency. However, this transformation also…Continue reading on Medium »
Read more...
The shift to remote work has revolutionized the modern workplace, providing flexibility and efficiency. However, this transformation also…Continue reading on Medium »
Read more...
Medium
“Insider Threats in the Remote Work Era Challenges and Solutions”
The shift to remote work has revolutionized the modern workplace, providing flexibility and efficiency. However, this transformation also…
“The Role of Employee Monitoring in Mitigating Insider Threats”
As organizations navigate the evolving landscape of cybersecurity, the specter of insider threats looms large. Insider threats, whether…Continue reading on Medium »
Read more...
As organizations navigate the evolving landscape of cybersecurity, the specter of insider threats looms large. Insider threats, whether…Continue reading on Medium »
Read more...
Medium
“The Role of Employee Monitoring in Mitigating Insider Threats”
As organizations navigate the evolving landscape of cybersecurity, the specter of insider threats looms large. Insider threats, whether…
#3 Set-up FoxyProxy in Firefox — Guide for Burp Suite
This article is a part of the Guide for Burp Suite series. Within the previous article, we see learn about the Different tools that are…Continue reading on Medium »
Read more...
This article is a part of the Guide for Burp Suite series. Within the previous article, we see learn about the Different tools that are…Continue reading on Medium »
Read more...
Medium
#3 Set-up FoxyProxy in Firefox — Guide for Burp Suite
This article is a part of the Guide for Burp Suite series. Within the previous article, we see learn about the Different tools that are…
Domain Fronting using Firebase does not work
https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/
<!-- SC_OFF -->This is for edu purpose only. As the title I'm now researching to use Firebase as a proxy to forward traffic from the client to c2 using cobalt strike, but Firebase seem like does not forward body request containing data send from client to c2. I'm probably do the same as the tuts in this link https://www.redteam.cafe/red-team/domain-front/firebase-domain-front-hiding-c2-as-app-traffic, but it's doesn't work ? Is the Firebase auto clear body data to prevent us to use that as a proxy ? Thanks <!-- SC_ON --> submitted by /u/usserr2306 (https://www.reddit.com/user/usserr2306)
[link] (https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/) [comments] (https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/)
https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/
<!-- SC_OFF -->This is for edu purpose only. As the title I'm now researching to use Firebase as a proxy to forward traffic from the client to c2 using cobalt strike, but Firebase seem like does not forward body request containing data send from client to c2. I'm probably do the same as the tuts in this link https://www.redteam.cafe/red-team/domain-front/firebase-domain-front-hiding-c2-as-app-traffic, but it's doesn't work ? Is the Firebase auto clear body data to prevent us to use that as a proxy ? Thanks <!-- SC_ON --> submitted by /u/usserr2306 (https://www.reddit.com/user/usserr2306)
[link] (https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/) [comments] (https://www.reddit.com/r/redteamsec/comments/17zkn6x/domain_fronting_using_firebase_does_not_work/)
Evilgophish
https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/
<!-- SC_OFF -->hello im new to red teaming and i've been following a video in relation to MFA cookie stealing. its called evilgophish i've set up everything on the vps which im using. im trying to run the ./gophish script but its not running properly for some reason. please see the following attached to see like it should be running properly but it isn't working https://preview.redd.it/eutlrmhi2h1c1.png?width=949&format=png&auto=webp&s=5b714efe3992e226baa3b6bf26fb4d6c1be12994 <!-- SC_ON --> submitted by /u/SpecialistPea1136 (https://www.reddit.com/user/SpecialistPea1136)
[link] (https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/) [comments] (https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/)
https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/
<!-- SC_OFF -->hello im new to red teaming and i've been following a video in relation to MFA cookie stealing. its called evilgophish i've set up everything on the vps which im using. im trying to run the ./gophish script but its not running properly for some reason. please see the following attached to see like it should be running properly but it isn't working https://preview.redd.it/eutlrmhi2h1c1.png?width=949&format=png&auto=webp&s=5b714efe3992e226baa3b6bf26fb4d6c1be12994 <!-- SC_ON --> submitted by /u/SpecialistPea1136 (https://www.reddit.com/user/SpecialistPea1136)
[link] (https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/) [comments] (https://www.reddit.com/r/redteamsec/comments/17zksgj/evilgophish/)
“Insider Threats in the Remote Work Era Challenges and Solutions”
https://medium.com/@Land2Cyber/insider-threats-in-the-remote-work-era-challenges-and-solutions-2279da9e1809?source=rss------bug_bounty-5
https://medium.com/@Land2Cyber/insider-threats-in-the-remote-work-era-challenges-and-solutions-2279da9e1809?source=rss------bug_bounty-5
The shift to remote work has revolutionized the modern workplace, providing flexibility and efficiency. However, this transformation also…Continue reading on Medium » (https://medium.com/@Land2Cyber/insider-threats-in-the-remote-work-era-challenges-and-solutions-2279da9e1809?source=rss------bug_bounty-5)
“The Role of Employee Monitoring in Mitigating Insider Threats”
https://medium.com/@Land2Cyber/the-role-of-employee-monitoring-in-mitigating-insider-threats-0349ec2f1bf7?source=rss------bug_bounty-5
https://medium.com/@Land2Cyber/the-role-of-employee-monitoring-in-mitigating-insider-threats-0349ec2f1bf7?source=rss------bug_bounty-5
As organizations navigate the evolving landscape of cybersecurity, the specter of insider threats looms large. Insider threats, whether…Continue reading on Medium » (https://medium.com/@Land2Cyber/the-role-of-employee-monitoring-in-mitigating-insider-threats-0349ec2f1bf7?source=rss------bug_bounty-5)
#3 Set-up FoxyProxy in Firefox — Guide for Burp Suite
https://securitycipher.medium.com/3-set-up-foxyproxy-in-firefox-guide-for-burp-suite-ee9627b6f513?source=rss------bug_bounty-5
https://securitycipher.medium.com/3-set-up-foxyproxy-in-firefox-guide-for-burp-suite-ee9627b6f513?source=rss------bug_bounty-5
This article is a part of the Guide for Burp Suite series. Within the previous article, we see learn about the Different tools that are…Continue reading on Medium » (https://securitycipher.medium.com/3-set-up-foxyproxy-in-firefox-guide-for-burp-suite-ee9627b6f513?source=rss------bug_bounty-5)
MemTracer - Memory Scaner
http://www.kitploit.com/2023/11/memtracer-memory-scaner.html
http://www.kitploit.com/2023/11/memtracer-memory-scaner.html
MemTracer is a tool that offers live memory analysis (https://www.kitploit.com/search/label/Analysis) capabilities, allowing digital forensic (https://www.kitploit.com/search/label/Forensic) practitioners to discover (https://www.kitploit.com/search/label/Discover) and investigate stealthy attack traces hidden in memory. The MemTracer is implemented in Python language, aiming to detect reflectively loaded native .NET framework Dynamic-Link Library (DLL). This is achieved by looking for the following abnormal memory region’s characteristics: The state of memory pages flags in each memory region. Specifically, the MEM_COMMIT flag which is used to reserve memory pages for virtual memory use. The type of pages in the region. The MEM_MAPPED page type indicates that the memory pages within the region are mapped into the view of a section. The memory protection (https://www.kitploit.com/search/label/Protection) for the region. The PAGE_READWRITE protection to indicate that the memory region is readable and writable, which happens if Assembly.Load(byte[]) method is used to load a module into memory. The memory region contains a PE header.
The tool starts by scanning the running processes, and by analyzing the allocated memory regions characteristics to detect reflective DLL loading symptoms. Suspicious memory regions which are identified as DLL modules are dumped for further analysis and investigation.
Furthermore, the tool features the following options: Dump the compromised process. Export a JSON file that provides information about the compromised process, such as the process name, ID, path, size, and base address. Search for specific loaded module by name. Example python.exe memScanner.py [-h] [-r] [-m MODULE]
-h, --help show this help message and exit
-r, --reflectiveScan Looking for reflective DLL loading
-m MODULE, --module MODULE Looking for spcefic loaded DLL The script needs administrator privileges in order incepect all processes.
Download MemTracer (https://github.com/mayHamad/MemTracer)
The tool starts by scanning the running processes, and by analyzing the allocated memory regions characteristics to detect reflective DLL loading symptoms. Suspicious memory regions which are identified as DLL modules are dumped for further analysis and investigation.
Furthermore, the tool features the following options: Dump the compromised process. Export a JSON file that provides information about the compromised process, such as the process name, ID, path, size, and base address. Search for specific loaded module by name. Example python.exe memScanner.py [-h] [-r] [-m MODULE]
-h, --help show this help message and exit
-r, --reflectiveScan Looking for reflective DLL loading
-m MODULE, --module MODULE Looking for spcefic loaded DLL The script needs administrator privileges in order incepect all processes.
Download MemTracer (https://github.com/mayHamad/MemTracer)
Writeups of All Apprentice Labs in Portswigger — All Lab’s Solution| Karthikeyan Nagaraj
https://cyberw1ng.medium.com/writeups-of-all-apprentice-labs-in-portswigger-all-labs-solution-karthikeyan-nagaraj-a5f23fd0c87b?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/writeups-of-all-apprentice-labs-in-portswigger-all-labs-solution-karthikeyan-nagaraj-a5f23fd0c87b?source=rss------bug_bounty-5
The Blog Contains a series of all writeups of Apprentice labs in Portswigger with an Explanation of Each Vulnerability. Labs are solved…Continue reading on Medium » (https://cyberw1ng.medium.com/writeups-of-all-apprentice-labs-in-portswigger-all-labs-solution-karthikeyan-nagaraj-a5f23fd0c87b?source=rss------bug_bounty-5)
Writeups of All Apprentice Labs in Portswigger — All Lab’s Solution| Karthikeyan Nagaraj
The Blog Contains a series of all writeups of Apprentice labs in Portswigger with an Explanation of Each Vulnerability. Labs are solved…Continue reading on Medium »
Read more...
The Blog Contains a series of all writeups of Apprentice labs in Portswigger with an Explanation of Each Vulnerability. Labs are solved…Continue reading on Medium »
Read more...
Medium
Writeups of All Apprentice Labs in Portswigger — All Lab’s Solution| Karthikeyan Nagaraj
The Blog Contains a series of all writeups of Apprentice labs in Portswigger with an Explanation of Each Vulnerability. Labs are solved…