This media is not supported in your browser
VIEW IN TELEGRAM
Just released a new, fast-paced, interactive binary patching plugin for IDA Pro. Check out a small blurb about it on the @HexRaysSA blog: https://hex-rays.com/blog/introducing-the-patching-plugin/
Code: https://github.com/gaasedelen/patching
π£ret2systems
π@malwr
Code: https://github.com/gaasedelen/patching
π£ret2systems
π@malwr
Microsoft blocks VBA macros originating from Internet based on MOTW flag.
I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.
Threat Actors already do that.
https://github.com/mgeeky/PackMyPayload
π£mariuszbit
π@malwr
I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.
Threat Actors already do that.
https://github.com/mgeeky/PackMyPayload
π£mariuszbit
π@malwr
π2
This media is not supported in your browser
VIEW IN TELEGRAM
How can we run arbitrary code without allocating/overwriting executable memory? We "borrow" (abuse) instructions from ntdll.dll!
https://www.x86matthew.com/view_post?id=windows_no_exec
π£x86matthew
π@malwr
https://www.x86matthew.com/view_post?id=windows_no_exec
π£x86matthew
π@malwr
Today we published a new report on the new ModifiedElephant APT, and the years of attacks against groups and individuals in India.
Blog: https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
Full Report: https://assets.sentinelone.com/sentinellabs-apt/modified-elephant-apt
π£TomHegel
π@malwr
Blog: https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
Full Report: https://assets.sentinelone.com/sentinellabs-apt/modified-elephant-apt
π£TomHegel
π@malwr
SentinelOne
ModifiedElephant APT and a Decade of Fabricating Evidence
A previously unreported threat actor has been targeting civil society for over a decade. Read about how it operates and its relationships to other threats.
Good news for all the infosec community. Now you can Export/Import VT Collections into/from MISP Events π by
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
π£virustotal
π@malwr
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
π£virustotal
π@malwr
FTK Imager Version 4.7.1 released >>
https://accessdata.com/product-download/ftk-imager-version-4-7-1
π£chadtilbury
π@malwr
https://accessdata.com/product-download/ftk-imager-version-4-7-1
π£chadtilbury
π@malwr
Exterro
Data Risk Management - Data Discovery & Privacy Platform | Exterro
Exterro's powerful data risk management platform unifies e-discovery, privacy, data governance, digital forensics, and cybersecurity compliance toβ¦
Rewrote Simple Process Injection using HellsGate in C# for fun and learning :)
It involved parsing ntdll to find and map the syscall ids for the involved functions and use the syscall numbers to directly invoke the the corresponding syscall.
Github repo: https://github.com/sbasu7241/HellsGate
π£SoumyadeepBas12
π@malwr
It involved parsing ntdll to find and map the syscall ids for the involved functions and use the syscall numbers to directly invoke the the corresponding syscall.
Github repo: https://github.com/sbasu7241/HellsGate
π£SoumyadeepBas12
π@malwr
Here is my post about orphan file name entries found on exFAT volumes written using Linux or macOS. This means that file names (or their parts) of deleted files having their directory entries partially overwritten can be recovered. #DFIR
https://dfir.ru/2022/02/11/exfat-orphan-file-name-entries/
π£errno_fail
π@malwr
https://dfir.ru/2022/02/11/exfat-orphan-file-name-entries/
π£errno_fail
π@malwr
My DFIR Blog
exFAT: orphan file name entries
The exFAT file system was designed with Unicode file names and optional vendor-specific extensions in mind. To keep things simple, the file system specification allows the usage of multiple directoβ¦
Exploring Windows UAC Bypasses : Techniques and Detection Strategies :
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
π£binitamshah
π@malwr
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
π£binitamshah
π@malwr
RE tip of the day: There are many PDF entries that can be misused by malware. For example, /Action with a /Launch argument can be used to execute an application specified with a /F entry. Arguments can be added using /P entry.
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
The MISP cheat sheet has been updated with a representation overview showing how MISP is used to model a security incident. It's a usually a nifty overview when you don't have the time to read all of the documentation. #CTI #ThreatIntelligence
https://www.misp-project.org/misp-training/cheatsheet.pdf
π£MISPProject
π@malwr
https://www.misp-project.org/misp-training/cheatsheet.pdf
π£MISPProject
π@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
WATCH: Discover the social engineering tactics employed by #APT36 or #EarthKarkaddan actors in our latest video.
Read our full report here:
https://research.trendmicro.com/EarthKarkaddan
π£TrendMicroRSRCH
π@malwr
Read our full report here:
https://research.trendmicro.com/EarthKarkaddan
π£TrendMicroRSRCH
π@malwr
New #PEsieve/#HollowsHunter (v0.3.4): https://github.com/hasherezade/pe-sieve/releases/ & https://github.com/hasherezade/hollows_hunter/releases - with threads' callstack scan. Check it out!
π£hasherezade
π@malwr
π£hasherezade
π@malwr
BinDiff export is finally on its way : I hope to be able to publish an update in a week or twoβ¦
π£bSr43
π@malwr
π£bSr43
π@malwr
ADExplorerSnapshotβ€py updates:
- BloodHound 4.1+ output format support
- new output mode to dump all objects/attributes to NDJSON
https://github.com/c3c/ADExplorerSnapshot.py
π£c3c
π@malwr
- BloodHound 4.1+ output format support
- new output mode to dump all objects/attributes to NDJSON
https://github.com/c3c/ADExplorerSnapshot.py
π£c3c
π@malwr
GitHub
GitHub - c3c/ADExplorerSnapshot: ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHoundβ¦
ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-object dumping to NDJSON. - c3c/ADExplorerSnapshot