Antivirus-Artifacts: Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.
π£digicat
Nice work. Gimme crowdstrike falcon.
π€brandeded
π@malwr
π£digicat
Nice work. Gimme crowdstrike falcon.
π€brandeded
π@malwr
GitHub
GitHub - ethereal-vx/Antivirus-Artifacts: Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytesβ¦
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot. - ethereal-vx/Antivirus-Artifacts
Presentation State of C2 Matrix - 2021 - 88 C2 frameworks as of November 2021 up from 60 12 months prior
π£digicat
π@malwr
π£digicat
π@malwr
GitHub
presentations/2021-GRIMMCon0x6/State of C2 Matrix - 2021 - GRIMMCon0x6.pdf at main Β· jorgeorchilles/presentations
Slides and materials for conference presentations. Contribute to jorgeorchilles/presentations development by creating an account on GitHub.
How Secure Boot works on M1 series Macs
π£tnavda
Thanks for this! Iβd been scratching my head over some of those log entries, and it makes sense that as iBoot spins things up, xnu and friends are taking over their delegated tasks, but iBoot is still managing overall security.
Also interesting that things start from a single efficiency core and expand out, so late in the boot process.
This means that if someoneβs looking to mess with the process, vulnerabilities in loading the second efficiency core are prime real estate.
π€Em_Adespoton
π@malwr
π£tnavda
Thanks for this! Iβd been scratching my head over some of those log entries, and it makes sense that as iBoot spins things up, xnu and friends are taking over their delegated tasks, but iBoot is still managing overall security.
Also interesting that things start from a single efficiency core and expand out, so late in the boot process.
This means that if someoneβs looking to mess with the process, vulnerabilities in loading the second efficiency core are prime real estate.
π€Em_Adespoton
π@malwr
The Eclectic Light Company
How Secure Boot works on M1 series Macs
This article has now been extensively corrected and modified.
A bunch of updates to REMnux today (see π§΅ for details). Run "remnux upgrade" to get them.
π£REMnux
π@malwr
π£REMnux
π@malwr
Process injection via the KernelCallBackTable involves replacing original callback function by custom payload so that whenever the function is invoked, payload will be triggered. In this case the fnCOPYDATA callback function has been used.
C# code snippet: https://gist.github.com/sbasu7241/5dd8c278762c6305b4b2009d44d60c13
π£SoumyadeepBas12
π@malwr
C# code snippet: https://gist.github.com/sbasu7241/5dd8c278762c6305b4b2009d44d60c13
π£SoumyadeepBas12
π@malwr
Hashlookup forensic analyser version 0.8 released including a report functionality
π£digicat
π@malwr
π£digicat
π@malwr
GitHub
Release hashlookup-forensic-analyser version 0.8 released including a report functionality Β· hashlookup/hashlookup-forensic-analyser
hashlookup-forensic-analyser version 0.8 released including a report functionality
A new --report option added to generate a report directory including a markdown summary and a JSON export of the r...
A new --report option added to generate a report directory including a markdown summary and a JSON export of the r...
Token Universe is an advanced tool that provides a wide range of possibilities to research Windows security mechanisms. It has a convenient interface for creating, viewing, and modifying access tokens, managing Local Security Authority and Security Account Manager's databases.
π£digicat
π@malwr
π£digicat
π@malwr
GitHub
GitHub - diversenok/TokenUniverse: An advanced tool for working with access tokens and Windows security policy.
An advanced tool for working with access tokens and Windows security policy. - diversenok/TokenUniverse
OpenDrop: An open Apple AirDrop implementation written in Python
https://github.com/seemoo-lab/opendrop
π£newsycombinator
π@malwr
https://github.com/seemoo-lab/opendrop
π£newsycombinator
π@malwr
GitHub
GitHub - seemoo-lab/opendrop: An open Apple AirDrop implementation written in Python
An open Apple AirDrop implementation written in Python - seemoo-lab/opendrop
Taking Water Cooler UX Into Your Own Hands With Ghidra
https://hackaday.com/2022/01/02/taking-water-cooler-ux-into-your-own-hands-with-ghidra/
π£hackaday
π@malwr
https://hackaday.com/2022/01/02/taking-water-cooler-ux-into-your-own-hands-with-ghidra/
π£hackaday
π@malwr
Hackaday
Taking Water Cooler UX Into Your Own Hands With Ghidra
Readers not aware of what Ghidra is might imagine some kind of aftermarket water cooler firmware or mainboard β a usual hacker practice with reflow ovens. What [Robbe Derks] did is no less imβ¦
For the new year I started a new blog post series on HyperGuard: PatchGuardβs lesser-known sibling:
https://windows-internals.com/hyperguard-secure-kernel-patch-guard-part-1-skpg-initialization/
π£yarden_shafir
π@malwr
https://windows-internals.com/hyperguard-secure-kernel-patch-guard-part-1-skpg-initialization/
π£yarden_shafir
π@malwr
Happy New Year! ππ π
Happy New Bug! πππ
https://bugs.chromium.org/p/project-zero/issues/detail?id=2223
https://bugs.chromium.org/p/project-zero/issues/detail?id=2235
π£natashenka
π@malwr
Happy New Bug! πππ
https://bugs.chromium.org/p/project-zero/issues/detail?id=2223
https://bugs.chromium.org/p/project-zero/issues/detail?id=2235
π£natashenka
π@malwr
I published a new blog post on βAutomated RE of Kernel Configurationsβ:
This also includes the release of a new BN plugin (link in blog post).
https://zznop.com/2022/01/02/automated-re-of-kernel-build-configs/
π£zznop_
π@malwr
This also includes the release of a new BN plugin (link in blog post).
https://zznop.com/2022/01/02/automated-re-of-kernel-build-configs/
π£zznop_
π@malwr
Automated RE of Kernel Configurations
π£zznop_
Pretty nice but seems to be somewhat manual process. I think somewhere on Twitter(?) I saw an idea of bruteforcing/bisecting the kconfig by building multiple variations of the kernel with different kconfig settings and comparing it against the image you have.
π€igor_sk
π@malwr
π£zznop_
Pretty nice but seems to be somewhat manual process. I think somewhere on Twitter(?) I saw an idea of bruteforcing/bisecting the kconfig by building multiple variations of the kernel with different kconfig settings and comparing it against the image you have.
π€igor_sk
π@malwr
Optimizing Windows Function Resolving: A Case Study Into GetProcAddress - phasetw0
π£dmchell
π@malwr
π£dmchell
π@malwr
Phasetw0
Optimizing Windows Function Resolving: A Case Study Into GetProcAddress - phasetw0
It was a cold winter morning. hypervis0r had just woken up at 1 AM because his sleep schedule was royally fucked, and he hopped onto the private...
AccChecker LOLBIN [AccCheckConsole.exe - load a managed DLL](https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340)
π£digicat
π@malwr
π£digicat
π@malwr
Gist
AccChecker LOLBIN [AccCheckConsole.exe]
AccChecker LOLBIN [AccCheckConsole.exe]. GitHub Gist: instantly share code, notes, and snippets.
WHAT?! π
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
π£0gtweet
π@malwr
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
π£0gtweet
π@malwr