Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
EDRHunt scans Windows services, drivers, processes, registry (https://www.kitploit.com/search/label/Registry) for installed EDRs (Endpoint Detection And Response). Read more about EDRHunt here (https://www.fourcore.vision/blogs/Red-Team-Adventure:-Digging-into-Windows-Endpoints-for-EDRs-and-profit-cUf).
Install Binary Download the latest release from the release section. Releases are built for windows/amd64. Go Requires Go to be installed on system. Tested on Go1.17+. go install github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt@master Usage Find installed EDRs $ .\EDRHunt.exe scan
[EDR]
Detected EDR: Windows Defender
Detected EDR: Kaspersky Security
Scan Everything $ .\EDRHunt.exe all
Running in user mode, escalate to admin for more details.
Scanning processes, services, drivers, and registry...
[PROCESSES]

Suspicious Process Name: MsMpEng.exe
Description: MsMpEng.exe
Caption: MsMpEng.exe
Binary:
ProcessID: 6764
Parent Process: 1148
Process CmdLine :
File Metadata:
Matched Keyword: [msmpeng]


Suspicious Process Name: NisSrv.exe
Description: NisSrv.exe
Caption: NisSrv.exe
Binary:
ProcessID: 9840
Parent Process: 1148
Process CmdLine :
File Metadata:
Matched Keyword: [nissrv]
...
Find drivers matching EDR keywords Microsoft Corporation FileDescription: Microsoft antimalware (https://www.kitploit.com/search/label/AntiMalware) file system filter driver ProductVersion: 4.18.2109.6 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks: Matched Keyword: [antimalware malware] Suspicious Driver Module: hvsifltr.sys Driver FilePath: c:\windows\system32\drivers\hvsifltr.sys Driver File Metadata: ProductName: Microsoft® Windows® Operating System OriginalFileName: hvsifltr.sys.mui InternalFileName: hvsifltr.sys Company Name: Microsoft Corporation FileDescription: Microsoft Defender (https://www.kitploit.com/search/label/Defender) Application Guard Filter Driver ProductVersion: 10.0.19041.1 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks: Matched Keyword: [defender] Suspicious Driver Module: WdNisDrv.sys Driver FilePath: c:\windows\system32\drivers\wd\wdnisdrv.sys Driver File Metadata: ProductName: Microsoft® Windows® Operating System OriginalFileName: wdnisdrv.sys InternalFileName: wdnisdrv.sys Company Name: Microsoft Corporation FileDescription: Windows Defender (https://www.kitploit.com/search/label/Windows%20Defender) Network Stream Filter ProductVersion: 4.18.2109.6 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks: Matched Keyword: [defender] ..."> __________ ____ __ ____ ___ ________
/ ____/ __ \/ __ \ / / / / / / / | / /_ __/
/ __/ / / / / /_/ / / /_/ / / / / |/ / / /
/ /___/ /_/ / _, _/ / __ / /_/ / /| / / /
/_____/_____/_/ |_| /_/ /_/\____/_/ |_/ /_/

FourCore Labs (https://fourcore.vision) | Version: 1.1

Running in user mode, escalate to admin for more details.
[DRIVERS]
Suspicious Driver Module: WdFilter.sys
Driver FilePath: c:\windows\system32\drivers\wd\wdfilter.sys
Driver File Metadata:
ProductName: Microsoft® Windows® Operating System
OriginalFileName: WdFilter.sys
InternalFileName: WdFilter
Company Name: Microsoft Corporation
FileDescription: Microsoft antimalware file system filter driver
ProductVersion: 4.18.2109.6
Comments:
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademark s:
Matched Keyword: [antimalware malware]

Suspicious Driver Module: hvsifltr.sys
Driver FilePath: c:\windows\system32\drivers\hvsifltr.sys
Driver File Metadata:
ProductName: Microsoft® Windows® Operating System

___________________________
@hacking_Attack
@Hacking_Video
OriginalFileName: hvsifltr.sys.mui
InternalFileName: hvsifltr.sys
Company Name: Microsoft Corporation
FileDescription: Microsoft Defender Application Guard Filter Driver
ProductVersion: 10.0.19041.1
Comments:
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
Matched Keyword: [defender]

Suspicious Driver Module: WdNisDrv.sys
Driver FilePath: c:\windows\system32\drivers\wd\wdnisdrv.sys
Driver File Metadata:
ProductName: Microsoft® Windows® Operating System
OriginalFileName: wdnisdrv.sys
InternalFileName: wdnisdrv.sys
Company Name: Microsoft Corporation
FileDescription: Windows Defender Network Stream Filter
ProductVersion: 4.18.2109.6
Comments:
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
Matched Keyword: [defender]
...
Find services matching EDR keywords $ .\EDRHunt.exe -s
Find drivers matching EDR keywords $ .\EDRHunt.exe -d
Find registry keys matching EDR keywords $ .\EDRHunt.exe -r
Detections EDR Detections Currently Available Windows Defender Kaspersky Security Symantec Security Crowdstrike Security Mcafee Security Cylance Security Carbon Black SentinelOne FireEye Elastic EDR More to be added soon. Community Would appreciate if you ran EDRHunt on your own deployments and test the detections! Thanks.

Download EDRHunt (https://github.com/FourCoreLabs/EDRHunt)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Cyber Terrorism Is a Growing Threat & Governments Must Take Action

With its benefits of deniability, relatively low costs, and the ability to attack from anywhere, cyber terrorism will increasingly threaten civilians everywhere.
Dark Reading: Attacks/Breaches
Vulnerability Scanning Triples, Leading to Two-Thirds Fewer Flaws

Companies are scanning more applications for vulnerabilities — and more often.
Dark Reading: Attacks/Breaches
Threat Actors Revive 20-Year-Old Tactic in Microsoft 365 Phishing Attacks

Recent attacks involving so-called "right-to-left override" spoofing aimed at Microsoft 365 users show how attackers sometimes modify and improve old methods to try and stay one step ahead of defenders.
Dark Reading: Attacks/Breaches
Get Started on Continuous Compliance Ahead of PCI DSS v4.0

Here's what vendors can do to prepare in the time remaining before the final release of PCI DSS 4.0 this quarter.
hacking: security in practice
Obscured windows directories

I've been trying to a link or demo for a more advanced method of hiding directories in windows.

the presentation showed a method of overriding the .. within a directory. So when you'd type cd .. the user would be in a new directory instead of traveling back up the directory path. Can't remember if this was in a sans class or some online video.

My Google fu on what to search for ia driving me nuts, and hope someone can help me w a link I'd really appreciate it.

submitted by /u/malbaisee
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
why does remcos 1.7 pro edition dosent work ?

why doesn't it work i put my local ip my public ip and a no ip dns and it still dosent work it works of i tried it to me but if i sent it to a friend it dosent work the error

submitted by /u/EnvironmentSad1649
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video