This media is not supported in your browser
VIEW IN TELEGRAM
If you need to dump credentials from lsass.exe on a machine with defender ATP on it, or generally want to execute #mimikatz for another operation on that machine, check out the following POC from @zux0x3a (All creds to him).
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
SysmonSimulator - Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
GitHub
GitHub - ScarredMonk/SysmonSimulator: Sysmon event simulation utility which can be used to simulate the attacks to generate theβ¦
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams. - ScarredMonk/SysmonS...
Our paper on emulating basebands for security analysis has been accepted at NDSS! We found multiple critical pre-auth vulnerabilities in the 2G and 4G implementations on Samsung and MediaTek basebands.
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr
πJust published a new research analyzing the #SysJoker backdoor.
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
π1
yara: match x86 that appears to manually traverse the TEB/PEB/LDR data.
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
Useful logs for Incident Responders
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Procdump works against Defender with a simple rename. It quarantines the generated .dmp file but you have a few seconds to make a copy of it before it's removed.
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
Linux kernel exploit development tutorial
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
breaking-bits.gitbook.io
Linux kernel exploit development | Breaking Bits
Windows Defender AV allows Everyone to read the configured exclusions on the system π€¦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
New #SysJoker backdoor targets Windows, Linux and macOS
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Technical details on APT35 attempts to exploit Log4j vulnerability:
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
Malware development serie:
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β€4π₯2π1
Signed kernel drivers β Unguarded gateway to Windowsβ core | WeLiveSecurity
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
Welivesecurity
Signed kernel drivers β Unguarded gateway to Windowsβ core
ESET researchers look at malware that abuses vulnerabilities in kernel drivers and outline mitigation techniques against this type of exploitation
Anyone else aware that .asd files can contain macros? Literally just found out.
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
π¦ EtwTi-Syscall-Hook
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
GitHub
GitHub - paranoidninja/Process-Instrumentation-Syscall-Hook: A simple program to hook the current process to identify the manualβ¦
A simple program to hook the current process to identify the manual syscall executions on windows - paranoidninja/Process-Instrumentation-Syscall-Hook
[Tooling βοΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12βs gist. Thread execution via SendMessageA. Works for GUI processes βοΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr