Linux kernel exploit development tutorial
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
breaking-bits.gitbook.io
Linux kernel exploit development | Breaking Bits
Windows Defender AV allows Everyone to read the configured exclusions on the system π€¦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
New #SysJoker backdoor targets Windows, Linux and macOS
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Technical details on APT35 attempts to exploit Log4j vulnerability:
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
Malware development serie:
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β€4π₯2π1
Signed kernel drivers β Unguarded gateway to Windowsβ core | WeLiveSecurity
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
Welivesecurity
Signed kernel drivers β Unguarded gateway to Windowsβ core
ESET researchers look at malware that abuses vulnerabilities in kernel drivers and outline mitigation techniques against this type of exploitation
Anyone else aware that .asd files can contain macros? Literally just found out.
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
π¦ EtwTi-Syscall-Hook
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
GitHub
GitHub - paranoidninja/Process-Instrumentation-Syscall-Hook: A simple program to hook the current process to identify the manualβ¦
A simple program to hook the current process to identify the manual syscall executions on windows - paranoidninja/Process-Instrumentation-Syscall-Hook
[Tooling βοΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12βs gist. Thread execution via SendMessageA. Works for GUI processes βοΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Here's a #dfir #malware analysis of the Dridex anti-analysis methods of obfuscating API calls with hashing and vector exception handling
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
0ffset Training Solutions | Practical and Affordable Cyber Security Training
DRIDEX: Analysing API Obfuscation Through VEH | 0ffset
DRIDEX is one of the most famous and prevalent banking Trojans that dates back to around late 2014. Throughout its improvement and variations, DRIDEX has been successful in targeting the financial services sector to steal banking information and crucial userβ¦
I updated #IdaIFL plugin (v1.4.3): https://github.com/hasherezade/ida_ifl/releases/ - now you can load "*.imports.txt" report from #PEsieve into your IDB
π£hasherezade
π@malwr
π£hasherezade
π@malwr
πWe publish 6β£ #Yara rules to detect πͺ#HackTools that read / modifyπ₯οΈ #RDP system settings. The rules are deliberately not only limited to detect PE files since these modifications may also take place in scripts etc.
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr