An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278. Nice blog post from TrustedSec on detection engineering. Some nice SPL queries.
π£munrobotic
π@malwr
π£munrobotic
π@malwr
TrustedSec
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278
Figure 1 - CVE 2021-42287 and 2021-42278 Attack Path 1 Diagram While each detection strives for high fidelity and may be able stand on its own accord,β¦
π1
Introduction to x64 Linux Binary Exploitation (Part 1)
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
Medium
Introduction to x64 Linux Binary Exploitation (Part 1)
Basic Buffer Overflow (BoF)
RCLocals - Linux Startup Analyzer
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
RCLocals - Linux Startup Analyzer
π1
Network Forensics, Part 1: Wireshark Basics #wireshark #networkforensics #cybersecurity #cyberwarrior
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
π5
Malware News pinned Β«πππPlease forward posts to the other groups πππΒ»
This media is not supported in your browser
VIEW IN TELEGRAM
If you need to dump credentials from lsass.exe on a machine with defender ATP on it, or generally want to execute #mimikatz for another operation on that machine, check out the following POC from @zux0x3a (All creds to him).
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
SysmonSimulator - Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
GitHub
GitHub - ScarredMonk/SysmonSimulator: Sysmon event simulation utility which can be used to simulate the attacks to generate theβ¦
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams. - ScarredMonk/SysmonS...
Our paper on emulating basebands for security analysis has been accepted at NDSS! We found multiple critical pre-auth vulnerabilities in the 2G and 4G implementations on Samsung and MediaTek basebands.
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr
πJust published a new research analyzing the #SysJoker backdoor.
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
π1
yara: match x86 that appears to manually traverse the TEB/PEB/LDR data.
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
Useful logs for Incident Responders
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Procdump works against Defender with a simple rename. It quarantines the generated .dmp file but you have a few seconds to make a copy of it before it's removed.
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
Linux kernel exploit development tutorial
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
breaking-bits.gitbook.io
Linux kernel exploit development | Breaking Bits
Windows Defender AV allows Everyone to read the configured exclusions on the system π€¦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
New #SysJoker backdoor targets Windows, Linux and macOS
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr