Bypassing User-Mode Hooks and Direct Invocation of System Calls for Red Teams - @MDSecLabs
π£dmchell
π@malwr
π£dmchell
π@malwr
MDSec
Bypassing User-Mode Hooks and Direct Invocation of System Calls for Red Teams - MDSec
Introduction The motivation to bypass user-mode hooks initially began with improving the success rate of process injection. There can be legitimate reasons to perform injection. UI Automation and Active Accessibility will use it...
Bypass Windows protection mechanisms & Playing with OffensiveNim
π£S3cur3Th1sSh1t
Good writeup! There are things in here I know a lot of companies would want to take a look at for their own security.
π€PwnistryCR
Java strikes again lol
π€cluberti
This is a great explanation. Really great work so thank you!
π€flani00
π@malwr
π£S3cur3Th1sSh1t
Good writeup! There are things in here I know a lot of companies would want to take a look at for their own security.
π€PwnistryCR
Java strikes again lol
π€cluberti
This is a great explanation. Really great work so thank you!
π€flani00
π@malwr
s3cur3th1ssh1t.github.io
Bypassing Windows protection mechanisms & Playing with OffensiveNim | S3cur3Th1sSh1t
In this post Iβm telling a short story from an environment I faced some time ago and how to handle the situation bypassing Constrained Language Mode and Appl...
Monitoring with PowerShell: Monitoring Storage Sense
Hi all,
First off; I wish you all the best for the coming year. May it be filled with a 100% increase in MRR, no security incidents and lot's of easy clients.
As the year is ending I figured to release some blogs I still had waiting, this one is about StorageSense. Storage Sense is a sort of automated disk cleanup that works a lot more efficient than the standard disk cleanup. The blog can be found here https://www.cyberdrain.com/monitoring-with-powershell-monitoring-storage-sense-settings/.
Best wishes to you all! :)
π£Lime-TeGek
I currently deploy storage sense settings via GPO but Iβve been working on ways to monitor this and other things that probably require impersonation. Maybe even something older like like folder redirection status.
Iβm a little concerned about deploying something like this via RMM and being dependent package repo. (Both having the module and taking supply chain into account)
Is there anyway repackage a module like this into a single script?
π€mspit
2 two many doors. Nice ride.
π€Gatorvw
This is great. Thanks!
π€pinncomp
π@malwr
Hi all,
First off; I wish you all the best for the coming year. May it be filled with a 100% increase in MRR, no security incidents and lot's of easy clients.
As the year is ending I figured to release some blogs I still had waiting, this one is about StorageSense. Storage Sense is a sort of automated disk cleanup that works a lot more efficient than the standard disk cleanup. The blog can be found here https://www.cyberdrain.com/monitoring-with-powershell-monitoring-storage-sense-settings/.
Best wishes to you all! :)
π£Lime-TeGek
I currently deploy storage sense settings via GPO but Iβve been working on ways to monitor this and other things that probably require impersonation. Maybe even something older like like folder redirection status.
Iβm a little concerned about deploying something like this via RMM and being dependent package repo. (Both having the module and taking supply chain into account)
Is there anyway repackage a module like this into a single script?
π€mspit
2 two many doors. Nice ride.
π€Gatorvw
This is great. Thanks!
π€pinncomp
π@malwr
CyberDrain - Kelvin Tegelaar
Monitoring with PowerShell: Monitoring Storage Sense settings
So letβs talk about Storage Sense. Storage Sense is a new-ish feature in Windows 10 which should replace the standard disk cleanup utilities. It has a lot more power than just disk cleanup as it can detect how long files have been in use and react based onβ¦
Ways to practice Windows PrivEsc
Hello community,
I am not really good (awful to be honest) with windows privilege escalation, and i am looking for resources to practice it. Are there any VMs that can be downloaded for that purpose?
Thanks in advance.
Happy hacking :)
π£sakas4
Consider looking into the CRTP cert from Pen tester academy. I am currently working on this cert. there are many ways to escalate privileges locally on a windows machine but this cert focuses on NOT using exploits in order to escalate privileges in an enterprise network.
π€Redteamer1995
I am huge fan and admirer of Vulnhub myself but HTB is a bit more challenging and it makes your mind think like in a different way.
Vulnhub in general is easier than HTB. So, giving HTB a shot is not a bad idea.
π€skinny3l3phant
HTB VIP or OFF SEC Playground is must for practicing Windows boxes.
π€skinny3l3phant
π@malwr
Hello community,
I am not really good (awful to be honest) with windows privilege escalation, and i am looking for resources to practice it. Are there any VMs that can be downloaded for that purpose?
Thanks in advance.
Happy hacking :)
π£sakas4
Consider looking into the CRTP cert from Pen tester academy. I am currently working on this cert. there are many ways to escalate privileges locally on a windows machine but this cert focuses on NOT using exploits in order to escalate privileges in an enterprise network.
π€Redteamer1995
I am huge fan and admirer of Vulnhub myself but HTB is a bit more challenging and it makes your mind think like in a different way.
Vulnhub in general is easier than HTB. So, giving HTB a shot is not a bad idea.
π€skinny3l3phant
VMs that can be downloaded for that purpose?HTB VIP or OFF SEC Playground is must for practicing Windows boxes.
π€skinny3l3phant
π@malwr
reddit
Ways to practice Windows PrivEsc
Hello community, I am not really good (awful to be honest) with windows privilege escalation, and i am looking for resources to practice it. Are...
diodb: Open-source vulnerability disclosure and bug bounty program database by disclose.io
π£yesnet0
Met the diodb database while doing "contact tracing" for a CVE recently.
Now I use it to find random companies to look for bugs in, rather than the other way around.
Extremely fast to Ctrl+F through the json, rather than load up 50+ vendor websites.
π€docker-osx
π@malwr
π£yesnet0
Met the diodb database while doing "contact tracing" for a CVE recently.
Now I use it to find random companies to look for bugs in, rather than the other way around.
Extremely fast to Ctrl+F through the json, rather than load up 50+ vendor websites.
π€docker-osx
π@malwr
GitHub
GitHub - disclose/diodb: Open-source vulnerability disclosure and bug bounty program database
Open-source vulnerability disclosure and bug bounty program database - disclose/diodb
I just published my first step-by-step reverse engineering/game patching tutorial using Ghidra, x64dbg, and Python. I tried to make it fun & balance the technical aspects for newcomers to RE. I really hope it helps someone here. Feedback is appreciated.
π£0xFF0F
I nearly stopped watching instantly when you said "everybody in Cyber", but I stuck with it and really enjoyed it :) You're a natural teacher, I'm sure this will be a go-to video for many people getting into RE. Good job!
π€mrverybored
This is really good, already shared it with my ctf teams
π€cents02
π@malwr
π£0xFF0F
I nearly stopped watching instantly when you said "everybody in Cyber", but I stuck with it and really enjoyed it :) You're a natural teacher, I'm sure this will be a go-to video for many people getting into RE. Good job!
π€mrverybored
This is really good, already shared it with my ctf teams
π€cents02
π@malwr
YouTube
Reverse Engineering/Game Patching Tutorial: Full Res RollerCoaster Tycoon with Ghidra+x64dbg+Python
GitHub Repo: https://github.com/jeFF0Falltrades/Game-Patches/tree/master/rct_full_res
Time Markers:
00:00:00 - Introduction
00:01:57 - Target audience and caveats note
00:03:10 - Start of tutorial
00:07:08 - Loading the file into Ghidra/First steps of REβ¦
Time Markers:
00:00:00 - Introduction
00:01:57 - Target audience and caveats note
00:03:10 - Start of tutorial
00:07:08 - Loading the file into Ghidra/First steps of REβ¦
Reversing Go - Part 2
π£digicat
This can and should be great content, but it is written poorly imo. Almost like a manual. No engagement for the reader, not even an introduction (not even for the first part), mostly spewed assembly with assumptions and explanations. Some people might be into this though, so thanks!
π€saudi_hacker1337
π@malwr
π£digicat
This can and should be great content, but it is written poorly imo. Almost like a manual. No engagement for the reader, not even an introduction (not even for the first part), mostly spewed assembly with assumptions and explanations. Some people might be into this though, so thanks!
π€saudi_hacker1337
π@malwr
Beginners: Here is an Easy-To-Use Packet Sniffing Tool
Espionage: A Network Packet and Traffic Interceptor For Linux. Spoof ARP & Wiretap A Network.
https://github.com/DoubleThreatSecurity/Espionage
Espionage is a network packet sniffer that intercepts large amounts of data being passed through an interface. The tool allows users to to run normal and verbose traffic analysis that shows a live feed of traffic, revealing packet direction, protocols, flags, etc. Espionage can also spoof ARP so, all data sent by the target gets redirected through the attacker (MiTM). Espionage supports IPv4, TCP/UDP, ICMP, and HTTP. Espionage was written in Python 3.8 but it also supports version 3.6.
π£overflow1n
π@malwr
Espionage: A Network Packet and Traffic Interceptor For Linux. Spoof ARP & Wiretap A Network.
https://github.com/DoubleThreatSecurity/Espionage
Espionage is a network packet sniffer that intercepts large amounts of data being passed through an interface. The tool allows users to to run normal and verbose traffic analysis that shows a live feed of traffic, revealing packet direction, protocols, flags, etc. Espionage can also spoof ARP so, all data sent by the target gets redirected through the attacker (MiTM). Espionage supports IPv4, TCP/UDP, ICMP, and HTTP. Espionage was written in Python 3.8 but it also supports version 3.6.
π£overflow1n
π@malwr
GitHub
DoubleThreatSecurity/Espionage
A Network Packet and Traffic Interceptor For Linux. Spoof ARP & Wiretap A Network. - DoubleThreatSecurity/Espionage
Simple Ring-3 Rootkit To Hide Malware From The Windows Task Manager
https://github.com/josh0xA/HookTaskmgr
π£overflow1n
π@malwr
https://github.com/josh0xA/HookTaskmgr
π£overflow1n
π@malwr
GitHub
josh0xA/ring3-kit
Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation) - josh0xA/ring3-kit
Undocumented user account in Zyxel products (CVE-2020-29583)
π£digicat
π€¬ βAccording to Zyxel, the account was designed to deliver automatic firmware updates for access points via FTP.β
π€1128327
π@malwr
π£digicat
π€¬ βAccording to Zyxel, the account was designed to deliver automatic firmware updates for access points via FTP.β
π€1128327
π@malwr
GetPerms: An Android library to see permissions granted to (and requested by) an app, its installation date, and more!
π£0x4f0x770x610x690x73
π@malwr
π£0x4f0x770x610x690x73
π@malwr
GitHub
GitHub - 4f77616973/GetPerms: An Android wrapper library to quickly get app permissions and other package data.
An Android wrapper library to quickly get app permissions and other package data. - GitHub - 4f77616973/GetPerms: An Android wrapper library to quickly get app permissions and other package data.
Overthewire: Learn Hacking By Playing Games
π£spectnullbyte
Cool! Thanks for sharing this!
π€AtlanticDipper
π@malwr
π£spectnullbyte
Cool! Thanks for sharing this!
π€AtlanticDipper
π@malwr
Medium
Overthewire, Learn Hacking By Playing Games
If youβve spent enough time on the web searching for practical resources to learn how to hack, then you should know by now what a hustleβ¦