Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Red Team Security
Exploring Nim language - Writing a ransomware

submitted by /u/Fun_Preference1113
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Phishing Users to Take a Test - @MDSecLabs

submitted by /u/dmchell
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Tap tap… is this thing on? Creating a notification-service for Cobalt-Strike

submitted by /u/jeanc0re
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Microsoft Defender for Identity: AS-REP Roasting

Microsoft released a new detection for Microsoft Defender for Identity. The detection detects a malicious request for user accounts that do not require pre-authentication, also known as an AS-REP roasting attack. This blog post will briefly explain what an AS-REP roasting attack is and how to mitigate it.

https://thalpius.com/2021/03/05/microsoft-defender-for-identity-as-rep-roasting/

submitted by /u/thalpius
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
HAFNIUM targeting Exchange Servers with 0-day exploits - Microsoft Security

submitted by /u/dmchell
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
The difference between Powershell only & process specific AMSI bypasses

submitted by /u/S3cur3Th1sSh1t
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Writing a Custom Bootloader

submitted by /u/Kondencuotaspienas
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
All OWASP API Top 10 for Explained Interactively (In-browser experience).

submitted by /u/ahmedm0hamed007
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Elevate Arbitrary WRMSR To Kernel Execution

https://githacks.org/_xeroxz/msrexec

submitted by /u/ahmedm0hamed007
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Attacking MS Exchange Web Interfaces

submitted by /u/ahmedm0hamed007
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Detection and Hunting of Golden SAML Attack

submitted by /u/ahmedm0hamed007
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
How to export LAPS password with Powershell

submitted by /u/ahmedm0hamed007
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­
Red Team Security
Powershell+VBScript Post-Exploitation Tool w/ Persistence

https://github.com/jeffjbowie/Weaponry/blob/master/SlimLOLC2.ps1

After learning about concepts of "living off the land" as well as researching various threat feeds, I wanted to make a minimal tool for running commands from a URL, with added persistence.

* Check for "mutex" file in $env:temp
* If mutex doesn't exist, drops VBScript payload to $env:temp
* Clones an existing scheduled task label, appending random characters to end , being mindful of 255 character limitation.
* Upon execution of scheduled task , connects to C2 URL, running desired command in either Powershell or Windows Command Processor.

submitted by /u/jeff-j-bowie
[link] [comments]

πŸŽ­πŸ§‘πŸ»β€πŸ’»@hacking_AttackπŸ§‘πŸ»β€πŸ’»πŸŽ­