Hacking Articles Tips Tricks Videos Tutorials
TiEtwAgent_2-701354.gif
KitPloit - PenTest Tools!
TiEtwAgent - PoC Memory Injection Detection Agent Based On ETW, For Offensive And Defensive Research Purposes
http://3.bp.blogspot.com/-ys4m_fjKPsk/YNj1S5YhgdI/AAAAAAAAeMc/zfaBKl-lB-cmEFmG1ljpd2A1z5Cw5k2oACK4BGAYYCw/w640-h360/TiEtwAgent_2-701354.gif
This project was created to research, build and test different memory injection detection use cases and bypass techniques. The agent utilizes Microsoft-Windows-Threat-Intelligence event tracing provider, as a more modern and stable alternative to Userland-hooking, with the benefit of Kernel-mode visibility.
The project depends on the microsoft/krabsetw library for ETS setup and consumption.
An accompanying blog post can be found here: https://blog.redbluepurple.io/windows-security-research/kernel-tracing-injection-detection
Adding new detections
Detection functions can be easily added in
Setup instructions
Assuming you do not have a Microsoft-trusted signing certificate:
* Put your machine in the test signing mode with bcdedit
* Generate a self-signed certificate with ELAM and Code Signing EKU
* Sign TiEtwAgent.exe and your ELAM driver with the certificate
* ./TiEtwAgent install
* net start TiEtwAgent
* Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt
TODO
* PPL Service, event parsing
* First detection
* Detection lifecycle
* Risk based lifecycle
PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver
Special thanks to @pathtofile for the post here: https://blog.tofile.dev/2020/12/16/elam.html
Download TiEtwAgent
TiEtwAgent - PoC Memory Injection Detection Agent Based On ETW, For Offensive And Defensive Research Purposes
http://3.bp.blogspot.com/-ys4m_fjKPsk/YNj1S5YhgdI/AAAAAAAAeMc/zfaBKl-lB-cmEFmG1ljpd2A1z5Cw5k2oACK4BGAYYCw/w640-h360/TiEtwAgent_2-701354.gif
This project was created to research, build and test different memory injection detection use cases and bypass techniques. The agent utilizes Microsoft-Windows-Threat-Intelligence event tracing provider, as a more modern and stable alternative to Userland-hooking, with the benefit of Kernel-mode visibility.
The project depends on the microsoft/krabsetw library for ETS setup and consumption.
An accompanying blog post can be found here: https://blog.redbluepurple.io/windows-security-research/kernel-tracing-injection-detection
Adding new detections
Detection functions can be easily added in
DetectionLogic.cpp, and called from detect_event(GenericEvent evt)for any source event type. Support for new event fields can be easily added by appending their name to the map in GenericEventclass declaration.Setup instructions
Assuming you do not have a Microsoft-trusted signing certificate:
* Put your machine in the test signing mode with bcdedit
* Generate a self-signed certificate with ELAM and Code Signing EKU
* Sign TiEtwAgent.exe and your ELAM driver with the certificate
* ./TiEtwAgent install
* net start TiEtwAgent
* Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt
TODO
* PPL Service, event parsing
* First detection
* Detection lifecycle
* Risk based lifecycle
PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver
Special thanks to @pathtofile for the post here: https://blog.tofile.dev/2020/12/16/elam.html
Download TiEtwAgent
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
WANNA GET STARTED WITH CYBERSECURITY BUT DON’T KNOW WHERE TO BEGIN?
https://cdn-images-1.medium.com/max/1320/1*FkiDfjBBKw1Wq3x3YLyVPw.png
Like always, I was checking around the Try Hack Me website for my daily dose and came across a new room PRE SECURITY, which was completely…
Continue reading on Medium »
WANNA GET STARTED WITH CYBERSECURITY BUT DON’T KNOW WHERE TO BEGIN?
https://cdn-images-1.medium.com/max/1320/1*FkiDfjBBKw1Wq3x3YLyVPw.png
Like always, I was checking around the Try Hack Me website for my daily dose and came across a new room PRE SECURITY, which was completely…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Start hacking today with TryHackMe
https://cdn-images-1.medium.com/max/1122/1*bVklSxvgVeHpVcQmI1dnuA.png
Hello, today I would like to share with you guys this website tryhackme.com. I am relatively new to hacking being only a second-year…
Continue reading on Medium »
Start hacking today with TryHackMe
https://cdn-images-1.medium.com/max/1122/1*bVklSxvgVeHpVcQmI1dnuA.png
Hello, today I would like to share with you guys this website tryhackme.com. I am relatively new to hacking being only a second-year…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Thompson — Writeup
https://cdn-images-1.medium.com/max/1014/1*FN05pb6NgvgWXAuigu6oEQ.png
In this article, we will show how to exploit vulnerabilities to hack the Thompson machine developed for TryHackMe, available here.
Continue reading on Medium »
TryHackMe: Thompson — Writeup
https://cdn-images-1.medium.com/max/1014/1*FN05pb6NgvgWXAuigu6oEQ.png
In this article, we will show how to exploit vulnerabilities to hack the Thompson machine developed for TryHackMe, available here.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Using Holehe to hunt users using email address's
https://cdn-images-1.medium.com/max/2600/1*KHDt-j8AgUL128KXtTzIfA.png
Using Holehe to hunt users using email address’s and improve your osint investigation
Continue reading on Medium »
Using Holehe to hunt users using email address's
https://cdn-images-1.medium.com/max/2600/1*KHDt-j8AgUL128KXtTzIfA.png
Using Holehe to hunt users using email address’s and improve your osint investigation
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Kaseya Say’s ‘It’s Not a Supply Chain Attack’ and Releases Indicators of Compromises. — CyberWorkx
https://cdn-images-1.medium.com/max/797/0*1QxNe53umy288tBZ
Kaseya has confirmed in its recent notification that the attack is not really a supply chain attack and it has not found the evidence for…
Continue reading on Medium »
Kaseya Say’s ‘It’s Not a Supply Chain Attack’ and Releases Indicators of Compromises. — CyberWorkx
https://cdn-images-1.medium.com/max/797/0*1QxNe53umy288tBZ
Kaseya has confirmed in its recent notification that the attack is not really a supply chain attack and it has not found the evidence for…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Found this link on Google (search engine/browser). Why is it there, and is it dangerous?
It didn't really lead to anything. However, I don't know much about the deep/dark web, so if someone can enlighten me on whether this is dangerous or not, be it from a legal aspect or from a leaked information/virus aspect:
http://hwikis25cffertqe.onion.ly/wiki/index.php?title=My_Dearest_Self_with_Malice_Aforethought
(I've changed the hyperlink to Google just in case someone accidentally clicks on it).
Alternatively, you can Google it by searching the search term:
my dearest self with malice aforethought wiki (it's a manga name)
It'll show up as the second result.
submitted by /u/supersaiyan491
[link] [comments]
Found this link on Google (search engine/browser). Why is it there, and is it dangerous?
It didn't really lead to anything. However, I don't know much about the deep/dark web, so if someone can enlighten me on whether this is dangerous or not, be it from a legal aspect or from a leaked information/virus aspect:
http://hwikis25cffertqe.onion.ly/wiki/index.php?title=My_Dearest_Self_with_Malice_Aforethought
(I've changed the hyperlink to Google just in case someone accidentally clicks on it).
Alternatively, you can Google it by searching the search term:
my dearest self with malice aforethought wiki (it's a manga name)
It'll show up as the second result.
submitted by /u/supersaiyan491
[link] [comments]
Install haktrails on Kali Linux
https://medium.com/@sherlock297/install-haktrails-on-kali-linux-9d53c7b9742b?source=rss------bug_bounty-5
haktrails : (subdomain) recon tool for bug bounty.Continue reading on Medium » (https://medium.com/@sherlock297/install-haktrails-on-kali-linux-9d53c7b9742b?source=rss------bug_bounty-5)
https://medium.com/@sherlock297/install-haktrails-on-kali-linux-9d53c7b9742b?source=rss------bug_bounty-5
haktrails : (subdomain) recon tool for bug bounty.Continue reading on Medium » (https://medium.com/@sherlock297/install-haktrails-on-kali-linux-9d53c7b9742b?source=rss------bug_bounty-5)
Introducing Bug Bounty Program for Oraichain and its ecosystem
https://blog.orai.io/introducing-bug-bounty-program-for-oraichain-and-its-ecosystem-6f65316ef0d?source=rss------bug_bounty-5
https://blog.orai.io/introducing-bug-bounty-program-for-oraichain-and-its-ecosystem-6f65316ef0d?source=rss------bug_bounty-5
Oraichain recognizes the community’s value in bringing security and completeness to Oraichain and its ecosystem. We welcome and seek to…Continue reading on Oraichain » (https://blog.orai.io/introducing-bug-bounty-program-for-oraichain-and-its-ecosystem-6f65316ef0d?source=rss------bug_bounty-5)