Red Team Security
HAFNIUM targeting Exchange Servers with 0-day exploits - Microsoft Security
submitted by /u/dmchell
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
HAFNIUM targeting Exchange Servers with 0-day exploits - Microsoft Security
submitted by /u/dmchell
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
The difference between Powershell only & process specific AMSI bypasses
submitted by /u/S3cur3Th1sSh1t
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
The difference between Powershell only & process specific AMSI bypasses
submitted by /u/S3cur3Th1sSh1t
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Writing a Custom Bootloader
submitted by /u/Kondencuotaspienas
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Writing a Custom Bootloader
submitted by /u/Kondencuotaspienas
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Window Privilege Escalation: Automated Script
https://www.hackingarticles.in/window-privilege-escalation-automated-script
@ahmedm0hamed101
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Window Privilege Escalation: Automated Script
https://www.hackingarticles.in/window-privilege-escalation-automated-script
@ahmedm0hamed101
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
All OWASP API Top 10 for Explained Interactively (In-browser experience).
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
All OWASP API Top 10 for Explained Interactively (In-browser experience).
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
ScareCrow - Payload Creation Framework Designed Around EDR Bypass
https://github.com/optiv/ScareCrow
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ScareCrow - Payload Creation Framework Designed Around EDR Bypass
https://github.com/optiv/ScareCrow
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Elevate Arbitrary WRMSR To Kernel Execution
https://githacks.org/_xeroxz/msrexec
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Elevate Arbitrary WRMSR To Kernel Execution
https://githacks.org/_xeroxz/msrexec
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Attacking MS Exchange Web Interfaces
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Attacking MS Exchange Web Interfaces
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Exploring a New Detection Evasion Technique on Linux
https://codemuch.tech/2021/02/25/exploring-linux-evasion/
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Exploring a New Detection Evasion Technique on Linux
https://codemuch.tech/2021/02/25/exploring-linux-evasion/
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Detection and Hunting of Golden SAML Attack
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Detection and Hunting of Golden SAML Attack
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
How to export LAPS password with Powershell
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
How to export LAPS password with Powershell
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Powershell+VBScript Post-Exploitation Tool w/ Persistence
https://github.com/jeffjbowie/Weaponry/blob/master/SlimLOLC2.ps1
After learning about concepts of "living off the land" as well as researching various threat feeds, I wanted to make a minimal tool for running commands from a URL, with added persistence.
* Check for "mutex" file in
* If mutex doesn't exist, drops VBScript payload to
* Clones an existing scheduled task label, appending random characters to end , being mindful of 255 character limitation.
* Upon execution of scheduled task , connects to C2 URL, running desired command in either Powershell or Windows Command Processor.
submitted by /u/jeff-j-bowie
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Powershell+VBScript Post-Exploitation Tool w/ Persistence
https://github.com/jeffjbowie/Weaponry/blob/master/SlimLOLC2.ps1
After learning about concepts of "living off the land" as well as researching various threat feeds, I wanted to make a minimal tool for running commands from a URL, with added persistence.
* Check for "mutex" file in
$env:temp* If mutex doesn't exist, drops VBScript payload to
$env:temp* Clones an existing scheduled task label, appending random characters to end , being mindful of 255 character limitation.
* Upon execution of scheduled task , connects to C2 URL, running desired command in either Powershell or Windows Command Processor.
submitted by /u/jeff-j-bowie
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Dump lsass with Windows OS native tools
submitted by /u/cx-4
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Dump lsass with Windows OS native tools
submitted by /u/cx-4
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
One thousand and one ways to copy your shellcode to memory (VBA Macros)
submitted by /u/NoUseForANick
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
One thousand and one ways to copy your shellcode to memory (VBA Macros)
submitted by /u/NoUseForANick
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
IronNetInjector: Turlaβs New Malware Loading Tool
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
IronNetInjector: Turlaβs New Malware Loading Tool
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
First example of malicious code that natively targets Apple Silicon (M1)
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
First example of malicious code that natively targets Apple Silicon (M1)
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Masslogger campaigns exfiltrates user credentials
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Masslogger campaigns exfiltrates user credentials
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
Exposed Unsafe ActiveX Method [CWE-618]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*4ZaQXs_vH6lIlM6jvuFR9Q.jpeg
Exposed Unsafe ActiveX Method weakness describes exposure of dangerous ActiveX methods that perform actions outside the browserβs securityβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Exposed Unsafe ActiveX Method [CWE-618]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*4ZaQXs_vH6lIlM6jvuFR9Q.jpeg
Exposed Unsafe ActiveX Method weakness describes exposure of dangerous ActiveX methods that perform actions outside the browserβs securityβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
IDOR Vulenebility with empty response still exposing sensitive details of customers!
Hello thereπ!
For many days I was thinking of sharing my bug bounty experience with the community and finally writing my first write-up.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
IDOR Vulenebility with empty response still exposing sensitive details of customers!
Hello thereπ!
For many days I was thinking of sharing my bug bounty experience with the community and finally writing my first write-up.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
NULL Pointer Dereference [CWE-476]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*QC2szUXNDa3JsW7LEeQ0YA.jpeg
NULL Pointer Dereference weakness occurs where software dereferences a pointer with a value of NULL instead of a valid address.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
NULL Pointer Dereference [CWE-476]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*QC2szUXNDa3JsW7LEeQ0YA.jpeg
NULL Pointer Dereference weakness occurs where software dereferences a pointer with a value of NULL instead of a valid address.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π