A curated list of Frida resources!
https://github.com/dweinstein/awesome-frida
#frida #android #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/dweinstein/awesome-frida
#frida #android #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
Short writeup on incident response case management, DFIR-IRIS (by @AirbusCyber / @White_Kernel ) and a bit of MISP ( @MISPProject ) #DFIR #CSIRT
https://www.vanimpe.eu/2022/01/05/incident-response-case-management-dfir-iris-and-misp/
π£cudeso
π@malwr
https://www.vanimpe.eu/2022/01/05/incident-response-case-management-dfir-iris-and-misp/
π£cudeso
π@malwr
www.vanimpe.eu
Incident response case management, DFIR-IRIS and a bit of MISP
Incident response case management, DFIR-IRIS and a bit of MISP - Koen Van Impe - vanimpe.eu - Incident response case management A good case management is indispensable for CSIRTs. There are a number of excellent case management tools available but
Check Medusa's New script additions for SSL Unpinning / Dex Dump from Memory / Log4j test / Dex Class Loader hooks
https://github.com/Ch0pin/medusa
π£Ch0pin
π@malwr
https://github.com/Ch0pin/medusa
π£Ch0pin
π@malwr
GitHub
GitHub - Ch0pin/medusa: Mobile Edge-Dynamic Unified Security Analysis
Mobile Edge-Dynamic Unified Security Analysis. Contribute to Ch0pin/medusa development by creating an account on GitHub.
I've been maintaining a repo for interesting malware samples, artifacts and even exercises! Check it out on Github!
π https://github.com/jstrosch/malware-samples
π£jstrosch
π@malwr
π https://github.com/jstrosch/malware-samples
π£jstrosch
π@malwr
Bcdedit /set {default} hypervisorloadoptions "EARLYKDINIT" this command allowed me to attach windbg to hyper-v successfully after struggling with win11. Incase it helps anyone..
π£Essb33
π@malwr
π£Essb33
π@malwr
Did you ever want to load dbk64.sys yourself and abuse the fact that it's a signed driver?
Maybe call the builtin kernel read/write (and many more!) routines because you don't have a driver signing certificate?
You can do that now! Check it out ;)
GitHub: https://github.com/ioncodes/ceload
π£layle_ctf
π@malwr
Maybe call the builtin kernel read/write (and many more!) routines because you don't have a driver signing certificate?
You can do that now! Check it out ;)
GitHub: https://github.com/ioncodes/ceload
π£layle_ctf
π@malwr
Paper &Code of LiveOverflow and my ROOTS paper about fuzzing of Smart Contract VMs is out!
Peak Web 3.0: A Memory corruption in a VM _written in C#_ π
https://github.com/fgsect/NeoDiff/blob/main/roots21-2.pdf
π£domenuk
π@malwr
Peak Web 3.0: A Memory corruption in a VM _written in C#_ π
https://github.com/fgsect/NeoDiff/blob/main/roots21-2.pdf
π£domenuk
π@malwr
My analysis blog for #Rook #Ransomware is out!
Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!
https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin ππ©
π£cPeterr
π@malwr
Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!
https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin ππ©
π£cPeterr
π@malwr
Happy new year, everyone! We start out the year with a small update: introducing the MISP report format as an export, also accessible via the API. Example: https://www.filescan.io/uploads/61d83f6e02e388f9fdb30dee/reports/517c82d9-6299-414d-a6b6-ce8b590efaee/overview annot: STIX/HTML/PDF will be following soon!
π£filescan_itsec
π@malwr
π£filescan_itsec
π@malwr
I've been part of @Google's Detection & Response team for almost 12 years now (π±) -- the 2 biggest advancements in my time, hands down: 1) remote live forensics ( and 2) enriched & automated investigations, which I hope to talk about more at some point.
https://github.com/google/grr
π£methodtim
π@malwr
https://github.com/google/grr
π£methodtim
π@malwr
GitHub
GitHub - google/grr: GRR Rapid Response: remote live forensics for incident response
GRR Rapid Response: remote live forensics for incident response - google/grr
New research! Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
Bill Demirkapi's Blog
Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
In the middle of August 2021, a special Word document was uploaded to VirusTotal by a user from Argentina. Although it was only detected by a single antivirus engine at the time, this sample turned out to be exploiting a zero day vulnerability in Microsoftβ¦
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
(I know many do this) If you're jamming on YARA locally, I recommend using VS Code & the awesome YARA extension which helps do syntax stuff, highlighting and more. Then use the integrated terminal to test and tweak your rules. Super fun.
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
Rook Ransomware https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
π£ptracesecurity
π@malwr
π£ptracesecurity
π@malwr