Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Atomic-Operator : A Python Package Is Used To Execute Atomic Red Team Tests
Additionally,
* Generating alerts to test products
* Testing EDR and other security tools
* Identifying way to perform defensive evasion from an adversary perspective
* Plus more. Features* Support local and remote execution of Atomic Red Teams tests on Windows, macOS, and Linux systems
* Supports running atomic-tests against
* Assist with downloading the atomic-red-team repository
* Can be automated further based on a configuration file
* A command-line and importable Python package
* Select specific tests when one or more techniques are specified
* Plus more Getting Started
If you are wanting a PowerShell version, please checkout Invoke-AtomicRedTeam
pip install atomic-operator
The next steps will guide you through setting up and running
* Get Atomics Install / clone Atomic Red Team repository
* atomic-operator Understand the options availble in atomic-operator
* Running Test on Command Line or Running Tests within a Script
* Running Tests via Configuration File InstallationYou can install atomic-operator on OS X, Linux, or Windows. You can also install it directly from the source. To install, see the commands under the relevant operating system heading, below. PrerequisitesThe following libraries are required and installed by atomic-operator:
pyyaml==5.4.1
fire==0.4.0
requests==2.26.0
attrs==21.2.0
pick==1.2.0
macOS, Linux and Windows:
pip install atomic-operator
macOS using M1 processor
git clone https://github.com/swimlane/atomic-operator.git
cd atomic-operator
Satisfy ModuleNotFoundError: No module named ‘setuptools_rust’
brew install rust
pip3 install –upgrade pip
pip3 install setuptools_rust
Back to our regularly scheduled programming . . .
pip install -r requirements.txt
python setup.py install
Installing from source
git clone https://github.com/swimlane/atomic-operator.git
cd atomic-operator
pip install -r requirements.txt
python setup.py install Usage example (command line)You can run
atomic-operator –help
atomic-operator run — –help Retrieving Atomic TestsIn order to use
atomic-operator get_atomics
You can specify the destination directory by using the –destination flag
atomic-operator get_atomics –destination “/tmp/some_directory” Running Tests LocallyIn order to run a test you must provide some additional properties (and options if desired). The main method to run tests is named
This will run ALL tests compatiable with your local operating system
atomic-operator run –atomics-path “/tmp/some_directory/redcanaryco-atomic-red-team-3700624”
You can select individual tests when you provide one or more specific techniques. For example running the following on the command line:
atomic-operator run –techniques[...]
___________________________
@hacking_Attack
@Hacking_Video
Atomic-Operator : A Python Package Is Used To Execute Atomic Red Team Tests
atomic-operatorenables security professionals to test their detection and defensive capabilities against prescribed techniques defined within atomic-red-team. By utilizing a testing framework such as atomic-operator, you can identify both your defensive capabilities as well as gaps in defensive coverage.Additionally,
atomic-operatorcan be used in many other situations like:* Generating alerts to test products
* Testing EDR and other security tools
* Identifying way to perform defensive evasion from an adversary perspective
* Plus more. Features* Support local and remote execution of Atomic Red Teams tests on Windows, macOS, and Linux systems
* Supports running atomic-tests against
iaas:aws* Can prompt for input arguments but not required* Assist with downloading the atomic-red-team repository
* Can be automated further based on a configuration file
* A command-line and importable Python package
* Select specific tests when one or more techniques are specified
* Plus more Getting Started
atomic-operatoris a Python-only package hosted on PyPi and works with Python 3.6 and greater.If you are wanting a PowerShell version, please checkout Invoke-AtomicRedTeam
pip install atomic-operator
The next steps will guide you through setting up and running
atomic-operator.* Get Atomics Install / clone Atomic Red Team repository
* atomic-operator Understand the options availble in atomic-operator
* Running Test on Command Line or Running Tests within a Script
* Running Tests via Configuration File InstallationYou can install atomic-operator on OS X, Linux, or Windows. You can also install it directly from the source. To install, see the commands under the relevant operating system heading, below. PrerequisitesThe following libraries are required and installed by atomic-operator:
pyyaml==5.4.1
fire==0.4.0
requests==2.26.0
attrs==21.2.0
pick==1.2.0
macOS, Linux and Windows:
pip install atomic-operator
macOS using M1 processor
git clone https://github.com/swimlane/atomic-operator.git
cd atomic-operator
Satisfy ModuleNotFoundError: No module named ‘setuptools_rust’
brew install rust
pip3 install –upgrade pip
pip3 install setuptools_rust
Back to our regularly scheduled programming . . .
pip install -r requirements.txt
python setup.py install
Installing from source
git clone https://github.com/swimlane/atomic-operator.git
cd atomic-operator
pip install -r requirements.txt
python setup.py install Usage example (command line)You can run
atomic-operatorfrom the command line or within your own Python scripts. To use atomic-operatorat the command line simply enter the following in your terminal:atomic-operator –help
atomic-operator run — –help Retrieving Atomic TestsIn order to use
atomic-operatoryou must have one or more atomic-red-team tests (Atomics) on your local system. atomic-operatorprovides you with the ability to download the Atomic Red Team repository. You can do so by running the following at the command line:atomic-operator get_atomics
You can specify the destination directory by using the –destination flag
atomic-operator get_atomics –destination “/tmp/some_directory” Running Tests LocallyIn order to run a test you must provide some additional properties (and options if desired). The main method to run tests is named
run.This will run ALL tests compatiable with your local operating system
atomic-operator run –atomics-path “/tmp/some_directory/redcanaryco-atomic-red-team-3700624”
You can select individual tests when you provide one or more specific techniques. For example running the following on the command line:
atomic-operator run –techniques[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Atomic-Operator : A Python Package Is Used To Execute ART Test
atomic-operator enables security professionals to test their detection and defensive capabilities against prescribed techniques.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Atomic-Operator : A Python Package Is Used To Execute Atomic Red Team Tests atomic-operatorenables security professionals to test their detection and defensive capabilities against prescribed techniques defined within atomic-red-team.…
T1564.001 –select_tests
Will prompt the user with a selection list of tests associated with that technique. A user can select one or more tests by using the space bar to highlight the desired test: Additional parametersYou can see additional parameters by running the following command:
atomic-operator run -- --help Parameter NameTypeDefaultDescriptiontechniqueslistallOne or more defined techniques by attack_technique ID.test_guidslistNoneOne or more Atomic test GUIDs.select_testsboolFalseSelect one or more atomic tests to run when a techniques are specified.atomics_pathstros.getcwd()The path of Atomic tests.check_prereqsboolFalseWhether or not to check for prereq dependencies (prereq_comand).get_prereqsboolFalseWhether or not you want to retrieve prerequisites.cleanupboolFalseWhether or not you want to run cleanup command(s).copy_source_filesboolTrueWhether or not you want to copy any related source (src, bin, etc.) files to a remote host.command_timeoutint20Time duration for each command before timeout.debugboolFalseWhether or not you want to output details about tests being ran.prompt_for_input_argsboolFalseWhether you want to prompt for input arguments for each test.return_atomicsboolFalseWhether or not you want to return atomics instead of running them.config_filestrNoneA path to a conifg_file which is used to automate atomic-operator in environments.config_file_onlyboolFalseWhether or not you want to run tests based on the provided config_file only.hostslistNoneA list of one or more remote hosts to run a test on.usernamestrNoneUsername for authentication of remote connections.passwordstrNonePassword for authentication of remote connections.ssh_key_pathstrNonePath to a SSH Key for authentication of remote connections.private_key_stringstrNoneA private SSH Key string used for authentication of remote connections.verify_sslboolFalseWhether or not to verify ssl when connecting over RDP (windows).ssh_portint22SSH port for authentication of remote connections.ssh_timeoutint5SSH timeout for authentication of remote connections.**kwargsdictNoneIf additional flags are passed into the run command then we will attempt to match them with defined inputs within Atomic tests and replace their value with the provided value.
You should see a similar output to the following:
NAME
atomic-operator run – The main method in which we run Atomic Red Team tests.
SYNOPSIS
atomic-operator run
DESCRIPTION
The main method in which we run Atomic Red Team tests.
FLAGS
–techniques=TECHNIQUES
Type: list
Default: [‘all’]
One or more defined techniques by attack_technique ID. Defaults to ‘all’.
–test_guids=TEST_GUIDS
Type: list
Default: []
One or more Atomic test GUIDs. Defaults to None.
–select_tests=SELECT_TESTS
Type: bool
Default: False
Select one or more tests from provided techniques. Defaults to False.
–atomics_path=ATOMICS_PATH
Default: ‘/U…
The path of Atomic tests. Defaults to os.getcwd().
–check_prereqs=CHECK_PREREQS
Default: False
Whether or not to check for prereq dependencies (prereq_comand). Defaults to False.
–get_prereqs=GET_PREREQS
Default: False
Whether or not you want to retrieve prerequisites. Defaults to False.
–cleanup=CLEANUP
Default: False
Whether or not you want to run cleanup command(s). Defaults to False.
–copy_source_files=COPY_SOURCE_FILES
Default: True
Whether or not you want to copy any related source (src, bin, etc.) files to a remote host. Defaults to True.
–command_timeout=COMMAND_TIMEOUT
Default: 20
Timeout duration for each command. Defaults to 20.
–debug=DEBUG
Default: False
Whether or not you want to output details about tests being ran. Defaults to False.
–prompt_for_input_args=PROMPT_FOR_INPUT_ARGS
Default: False
Whether you want to prompt for input arguments for each test. Defaults to False.
–return_atomics=RETURN_ATOMICS
Default: False
Whether or not you want to return atomics instead of running them. Defaults to False.
–config_file=CONFIG_FILE
Type: Optional[]
Default: None
A path to a conifg_file [...]
___________________________
@hacking_Attack
@Hacking_Video
Will prompt the user with a selection list of tests associated with that technique. A user can select one or more tests by using the space bar to highlight the desired test: Additional parametersYou can see additional parameters by running the following command:
atomic-operator run -- --help Parameter NameTypeDefaultDescriptiontechniqueslistallOne or more defined techniques by attack_technique ID.test_guidslistNoneOne or more Atomic test GUIDs.select_testsboolFalseSelect one or more atomic tests to run when a techniques are specified.atomics_pathstros.getcwd()The path of Atomic tests.check_prereqsboolFalseWhether or not to check for prereq dependencies (prereq_comand).get_prereqsboolFalseWhether or not you want to retrieve prerequisites.cleanupboolFalseWhether or not you want to run cleanup command(s).copy_source_filesboolTrueWhether or not you want to copy any related source (src, bin, etc.) files to a remote host.command_timeoutint20Time duration for each command before timeout.debugboolFalseWhether or not you want to output details about tests being ran.prompt_for_input_argsboolFalseWhether you want to prompt for input arguments for each test.return_atomicsboolFalseWhether or not you want to return atomics instead of running them.config_filestrNoneA path to a conifg_file which is used to automate atomic-operator in environments.config_file_onlyboolFalseWhether or not you want to run tests based on the provided config_file only.hostslistNoneA list of one or more remote hosts to run a test on.usernamestrNoneUsername for authentication of remote connections.passwordstrNonePassword for authentication of remote connections.ssh_key_pathstrNonePath to a SSH Key for authentication of remote connections.private_key_stringstrNoneA private SSH Key string used for authentication of remote connections.verify_sslboolFalseWhether or not to verify ssl when connecting over RDP (windows).ssh_portint22SSH port for authentication of remote connections.ssh_timeoutint5SSH timeout for authentication of remote connections.**kwargsdictNoneIf additional flags are passed into the run command then we will attempt to match them with defined inputs within Atomic tests and replace their value with the provided value.
You should see a similar output to the following:
NAME
atomic-operator run – The main method in which we run Atomic Red Team tests.
SYNOPSIS
atomic-operator run
DESCRIPTION
The main method in which we run Atomic Red Team tests.
FLAGS
–techniques=TECHNIQUES
Type: list
Default: [‘all’]
One or more defined techniques by attack_technique ID. Defaults to ‘all’.
–test_guids=TEST_GUIDS
Type: list
Default: []
One or more Atomic test GUIDs. Defaults to None.
–select_tests=SELECT_TESTS
Type: bool
Default: False
Select one or more tests from provided techniques. Defaults to False.
–atomics_path=ATOMICS_PATH
Default: ‘/U…
The path of Atomic tests. Defaults to os.getcwd().
–check_prereqs=CHECK_PREREQS
Default: False
Whether or not to check for prereq dependencies (prereq_comand). Defaults to False.
–get_prereqs=GET_PREREQS
Default: False
Whether or not you want to retrieve prerequisites. Defaults to False.
–cleanup=CLEANUP
Default: False
Whether or not you want to run cleanup command(s). Defaults to False.
–copy_source_files=COPY_SOURCE_FILES
Default: True
Whether or not you want to copy any related source (src, bin, etc.) files to a remote host. Defaults to True.
–command_timeout=COMMAND_TIMEOUT
Default: 20
Timeout duration for each command. Defaults to 20.
–debug=DEBUG
Default: False
Whether or not you want to output details about tests being ran. Defaults to False.
–prompt_for_input_args=PROMPT_FOR_INPUT_ARGS
Default: False
Whether you want to prompt for input arguments for each test. Defaults to False.
–return_atomics=RETURN_ATOMICS
Default: False
Whether or not you want to return atomics instead of running them. Defaults to False.
–config_file=CONFIG_FILE
Type: Optional[]
Default: None
A path to a conifg_file [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Puwr : SSH Pivoting Script For Expanding Attack Surfaces On Local Networks
Puwr will Easily expand your attack surface on a local network by discovering more hosts, via SSH. Using a machine running a SSH service, Puwr uses a given subnet range to scope out IP’s, sending back any successful ping requests it has. This can be used to create a pivoting attack from a compromised machine, by returning you hosts you couldn’t normally discover from your own device. Open ports can then be probed on these discovered devices, to find a gateway into attacking more devices.
Upcoming
Here are some new features I plan to add in along with the upcoming update.
* Scan for open ports of discovered hosts (DONE)
* Change CLI output to look more neat and organized (DONE)
* Enumerate information on “victim” host for privilege escalation
* Optional colored output
Usage
Puwr is simple to run, only requiring 4 flags:
example:
If you need to connect through a port other than 22, use the
If you want to keep quiet, use the
You can now use
Use the
The paramiko and netaddr modules are required for this script to work!
You can install them with the pip tool:
Here I scanned devices and checked which ones has port 80 and 443 open to target web applications.
Notice how the TTL number also displays, giving you a hint at what the device may be running on.
Tested Operating Systems
So far, I have only confirmed Puwr to work on a few operating systems:
* Kali Linux
* Parrot OS
* Windows 10
However, it should work on almost any OS with Python, and the needed modules installed.
Port Scanning
As mentioned earlier a few times, you can now not only discover hosts, but also scan them for open ports.
This can be used to find an attack vector on devices running an accessable service. By default, ports will not be scanned, but you can use the
Keep in mind however, that port scanning does take a good bit of additional time to complete. PORT SCANNING ONLY WORKS ON MACHINES WITH PYTHON 3 INSTALLED FOR NOW
Download
___________________________
@hacking_Attack
@Hacking_Video
Puwr : SSH Pivoting Script For Expanding Attack Surfaces On Local Networks
Puwr will Easily expand your attack surface on a local network by discovering more hosts, via SSH. Using a machine running a SSH service, Puwr uses a given subnet range to scope out IP’s, sending back any successful ping requests it has. This can be used to create a pivoting attack from a compromised machine, by returning you hosts you couldn’t normally discover from your own device. Open ports can then be probed on these discovered devices, to find a gateway into attacking more devices.
Upcoming
Here are some new features I plan to add in along with the upcoming update.
* Scan for open ports of discovered hosts (DONE)
* Change CLI output to look more neat and organized (DONE)
* Enumerate information on “victim” host for privilege escalation
* Optional colored output
Usage
Puwr is simple to run, only requiring 4 flags:
python3 puwr.py (MACHINE IP) (USER) (PASSWORD) (SUBNET VALUE)example:
python3 puwr.py 10.0.0.53 xeonrx password123 10.0.0.1/24If you need to connect through a port other than 22, use the
-pflag. (example: -p 2222)If you want to keep quiet, use the
-sflag to wait specified seconds between request. (example: -s 5)You can now use
--scanto discover open ports on discovered devices. (example: –scan 80 443)Use the
-hflag for usage reference in the script.The paramiko and netaddr modules are required for this script to work!
You can install them with the pip tool:
pip install netaddr paramikoHere I scanned devices and checked which ones has port 80 and 443 open to target web applications.
Notice how the TTL number also displays, giving you a hint at what the device may be running on.
Tested Operating Systems
So far, I have only confirmed Puwr to work on a few operating systems:
* Kali Linux
* Parrot OS
* Windows 10
However, it should work on almost any OS with Python, and the needed modules installed.
Port Scanning
As mentioned earlier a few times, you can now not only discover hosts, but also scan them for open ports.
This can be used to find an attack vector on devices running an accessable service. By default, ports will not be scanned, but you can use the
--scanflag, and add the port numbers you’d like to scan.Keep in mind however, that port scanning does take a good bit of additional time to complete. PORT SCANNING ONLY WORKS ON MACHINES WITH PYTHON 3 INSTALLED FOR NOW
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Puwr : SSH Pivoting Script For Expanding Attack Surfaces On Local net
Puwr will Easily expand your attack surface on a local network by discovering more hosts, via SSH. Using a machine running a SSH service
Hacking Articles Tips Tricks Videos Tutorials
T1564.001 –select_tests Will prompt the user with a selection list of tests associated with that technique. A user can select one or more tests by using the space bar to highlight the desired test: Additional parametersYou can see additional parameters by…
which is used to automate atomic-operator in environments. Default to None.
–config_file_only=CONFIG_FILE_ONLY
Default: False
Whether or not you want to run tests based on the provided config_file only. Defaults to False.
–hosts=HOSTS
Default: []
A list of one or more remote hosts to run a test on. Defaults to [].
–username=USERNAME
Type: Optional[]
Default: None
Username for authentication of remote connections. Defaults to None.
–password=PASSWORD
Type: Optional[]
Default: None
Password for authentication of remote connections. Defaults to None.
–ssh_key_path=SSH_KEY_PATH
Type: Optional[]
Default: None
Path to a SSH Key for authentication of remote connections. Defaults to None.
–private_key_string=PRIVATE_KEY_STRING
Type: Optional[]
Default: None
A private SSH Key string used for authentication of remote connections. Defaults to None.
–verify_ssl=VERIFY_SSL
Default: False
Whether or not to verify ssl when connecting over RDP (windows). Defaults to False.
–ssh_port=SSH_PORT
Default: 22
SSH port for authentication of remote connections. Defaults to 22.
–ssh_timeout=SSH_TIMEOUT
Default: 5
SSH timeout for authentication of remote connections. Defaults to 5.
Additional flags are accepted.
If provided, keys matching inputs for a test will be replaced. Default is None. Running atomic-operator using a config_fileIn addition to the ability to pass in parameters with
atomic_tests:
guid: f7e6ec05-c19e-4a80-a7e7-241027992fdb
input_arguments:
output_file:
value: custom_output.txt
input_file:
value: custom_input.txt
guid: 3ff64f0b-3af2-3866-339d-38d9791407c3
input_arguments:
second_arg:
value: SWAPPPED argument
guid: 32f90516-4bc9-43bd-b18d-2cbe0b7ca9b2 Usage example (scripts)from atomic_operator import AtomicOperator
operator = AtomicOperator()
This will download a local copy of the atomic-red-team repository
print(operator.get_atomics(‘/tmp/some_directory’))
this will run tests on your local system
operator.run(
technique: str=’All’,
atomics_path=os.getcwd(),
check_dependencies=False,
get_prereqs=False,
cleanup=False,
command_timeout=20,
debug=False,
prompt_for_input_args=False,
**kwargs
) Download
___________________________
@hacking_Attack
@Hacking_Video
–config_file_only=CONFIG_FILE_ONLY
Default: False
Whether or not you want to run tests based on the provided config_file only. Defaults to False.
–hosts=HOSTS
Default: []
A list of one or more remote hosts to run a test on. Defaults to [].
–username=USERNAME
Type: Optional[]
Default: None
Username for authentication of remote connections. Defaults to None.
–password=PASSWORD
Type: Optional[]
Default: None
Password for authentication of remote connections. Defaults to None.
–ssh_key_path=SSH_KEY_PATH
Type: Optional[]
Default: None
Path to a SSH Key for authentication of remote connections. Defaults to None.
–private_key_string=PRIVATE_KEY_STRING
Type: Optional[]
Default: None
A private SSH Key string used for authentication of remote connections. Defaults to None.
–verify_ssl=VERIFY_SSL
Default: False
Whether or not to verify ssl when connecting over RDP (windows). Defaults to False.
–ssh_port=SSH_PORT
Default: 22
SSH port for authentication of remote connections. Defaults to 22.
–ssh_timeout=SSH_TIMEOUT
Default: 5
SSH timeout for authentication of remote connections. Defaults to 5.
Additional flags are accepted.
If provided, keys matching inputs for a test will be replaced. Default is None. Running atomic-operator using a config_fileIn addition to the ability to pass in parameters with
atomic-operatoryou can also pass in a path to a config_filethat contains all the atomic tests and their potential inputs. You can see an example of this config_file here:atomic_tests:
guid: f7e6ec05-c19e-4a80-a7e7-241027992fdb
input_arguments:
output_file:
value: custom_output.txt
input_file:
value: custom_input.txt
guid: 3ff64f0b-3af2-3866-339d-38d9791407c3
input_arguments:
second_arg:
value: SWAPPPED argument
guid: 32f90516-4bc9-43bd-b18d-2cbe0b7ca9b2 Usage example (scripts)from atomic_operator import AtomicOperator
operator = AtomicOperator()
This will download a local copy of the atomic-red-team repository
print(operator.get_atomics(‘/tmp/some_directory’))
this will run tests on your local system
operator.run(
technique: str=’All’,
atomics_path=os.getcwd(),
check_dependencies=False,
get_prereqs=False,
cleanup=False,
command_timeout=20,
debug=False,
prompt_for_input_args=False,
**kwargs
) Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How did I make Quite Hacker the largest Active Cybe Security News Page on Instagram?
https://cdn-images-1.medium.com/max/688/1*oq5JxsJay1JUnXMIuKqFAQ.png
I’m sharing my 3 years of journey of starting this Quite Hacker page on instagram in this 4 minutes article.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How did I make Quite Hacker the largest Active Cybe Security News Page on Instagram?
https://cdn-images-1.medium.com/max/688/1*oq5JxsJay1JUnXMIuKqFAQ.png
I’m sharing my 3 years of journey of starting this Quite Hacker page on instagram in this 4 minutes article.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How did I make Quite Hacker the largest Active Cybe Security News Page on Instagram?
I’m sharing my 3 years of journey of starting this Quite Hacker page on instagram in this 4 minutes article.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
mac_changer-linux
https://cdn-images-1.medium.com/max/794/1*Vy1v75dBrRBt_mMaX32-bg.png
Hello, in this blog I am going to explain briefly my “mac_changer-linux” tool. This will be kind of a README file.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
mac_changer-linux
https://cdn-images-1.medium.com/max/794/1*Vy1v75dBrRBt_mMaX32-bg.png
Hello, in this blog I am going to explain briefly my “mac_changer-linux” tool. This will be kind of a README file.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
mac_changer-linux
Hello, in this blog I am going to explain briefly my “mac_changer-linux” tool. This will be kind of a README file.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Documentation Template using Cookiecutter, MkDocs, and GitHub Template
https://cdn-images-1.medium.com/max/1838/1*CK2PeFTUjtLMnPQtjWG-eQ.png
Create a project documentation template using Cookiecutter, MkDocs, and GitHub Template.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Documentation Template using Cookiecutter, MkDocs, and GitHub Template
https://cdn-images-1.medium.com/max/1838/1*CK2PeFTUjtLMnPQtjWG-eQ.png
Create a project documentation template using Cookiecutter, MkDocs, and GitHub Template.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Documentation Template using Cookiecutter, MkDocs, and GitHub Template
Create a project documentation template using Cookiecutter, MkDocs, and GitHub Template.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
10 Resources for beginners to learn Threat Hunting
https://cdn-images-1.medium.com/max/816/1*EH55fe9ibwLYEj1Ne3_2_w.png
Threat Hunting:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
10 Resources for beginners to learn Threat Hunting
https://cdn-images-1.medium.com/max/816/1*EH55fe9ibwLYEj1Ne3_2_w.png
Threat Hunting:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Resources for beginners to learn Threat Hunting
Threat Hunting:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Security Professional Summer Must-Read.
https://cdn-images-1.medium.com/max/2421/1*p0CkF3l4vfFlgBBWq9OFgA.jpeg
I'm in the mainframe. I'm bypassing the firewall. I’m in the system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
A Security Professional Summer Must-Read.
https://cdn-images-1.medium.com/max/2421/1*p0CkF3l4vfFlgBBWq9OFgA.jpeg
I'm in the mainframe. I'm bypassing the firewall. I’m in the system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A Security Professional Summer Must-Read.
I'm in the mainframe. I'm bypassing the firewall. I’m in the system.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HacktheBox[Nest]
https://cdn-images-1.medium.com/max/693/1*vJNRJvJgDhwwXb1JgiMOsQ.png
Although HTB was rated as an easy box, there were several points where a user can get stuck. Getting user involved heavy SMB enumeration…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HacktheBox[Nest]
https://cdn-images-1.medium.com/max/693/1*vJNRJvJgDhwwXb1JgiMOsQ.png
Although HTB was rated as an easy box, there were several points where a user can get stuck. Getting user involved heavy SMB enumeration…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HacktheBox[Nest]
Although HTB was rated as an easy box, there were several points where a user can get stuck. Getting user involved heavy SMB enumeration…
hacking: security in practice
Possible file less malware ?
I ran 2 av's but did not find any positives. However my 3rd av spotted 2 folders as malicious and deleted it. Upon completing the scan it detected an "unknow exe" which is unsigned and named "WMIADAP.EXE" with no physical exe whywhere. However the exe's location shows as "C:\?\C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" I tried to open the exe source folder but it says no folder like that exists. So i manually checked "C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" and an exe named "wmiadap.exe" exists but it is signed. I further checked using Task manager & Process explorer but both doesn't even show a process called WMIADAP.EXE to be running. I am not even able to upload to Virustotal since there is no exe saved anywhere! Should i delete or block it ? Possible fileless malware ? How do i even analyse it further ?
submitted by /u/zilla005
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Possible file less malware ?
I ran 2 av's but did not find any positives. However my 3rd av spotted 2 folders as malicious and deleted it. Upon completing the scan it detected an "unknow exe" which is unsigned and named "WMIADAP.EXE" with no physical exe whywhere. However the exe's location shows as "C:\?\C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" I tried to open the exe source folder but it says no folder like that exists. So i manually checked "C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" and an exe named "wmiadap.exe" exists but it is signed. I further checked using Task manager & Process explorer but both doesn't even show a process called WMIADAP.EXE to be running. I am not even able to upload to Virustotal since there is no exe saved anywhere! Should i delete or block it ? Possible fileless malware ? How do i even analyse it further ?
submitted by /u/zilla005
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Possible file less malware ?
I ran 2 av's but did not find any positives. However my 3rd av spotted 2 folders as malicious and deleted it. Upon completing the scan it detected...
hacking: security in practice
Let’s talk about ransomware-
Greetings, I have been working in defensive side of security. Lately, ransomware is the subject matter that interests me. So I have few questions regarding ransomware. 1. How do ransomware propagate from one network to another? 2. How to adversaries execute ransomware in a big companies? Breaking the infrastructure or simply tricking employees to execute it? Or other ways? 3. If you would make a ransomware what language would you use? And why? 4. Is XRD/EDR enough to stop ransomware?
submitted by /u/Inevitable-Tank-456
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Let’s talk about ransomware-
Greetings, I have been working in defensive side of security. Lately, ransomware is the subject matter that interests me. So I have few questions regarding ransomware. 1. How do ransomware propagate from one network to another? 2. How to adversaries execute ransomware in a big companies? Breaking the infrastructure or simply tricking employees to execute it? Or other ways? 3. If you would make a ransomware what language would you use? And why? 4. Is XRD/EDR enough to stop ransomware?
submitted by /u/Inevitable-Tank-456
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Let’s talk about ransomware-
Greetings, I have been working in defensive side of security. Lately, ransomware is the subject matter that interests me. So I have few questions...
hacking: security in practice
Is it known how some of the famous (decade old) Runescape hacks were done?
I recall a while ago there were very cool hacks in Runescape. One that I remember well was where someone was able to double the items that they had and made lots of party hat. Is there some explanation document or video that describes how that (or other big hacks) ware done?
submitted by /u/bersnin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it known how some of the famous (decade old) Runescape hacks were done?
I recall a while ago there were very cool hacks in Runescape. One that I remember well was where someone was able to double the items that they had and made lots of party hat. Is there some explanation document or video that describes how that (or other big hacks) ware done?
submitted by /u/bersnin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it known how some of the famous (decade old) Runescape hacks...
I recall a while ago there were very cool hacks in Runescape. One that I remember well was where someone was able to double the items that they...