Pentester
2.79K subscribers
116 photos
3 videos
163 files
2.76K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
An introduction to reverse engineering .NET AOT applications

https://harfanglab.io/en/insidethelab/reverse-engineering-ida-pro-aot-net/
🔥2
Windows CLFS Driver Privilege Escalation

This vulnerability targets the Common Log File System (CLFS) and allows attackers to escalate privileges and potentially fully compromise an organization’s Windows systems. In April 2023, Microsoft released a patch for this vulnerability and the CNA CVE-2023-28252 was assigned.

Affects version:
— Windows 11 21H2 (clfs.sys version 10.0.22000.1574);
— Windows 11 22H2;
— Windows 10 21H2;
— Windows 10 22H2;
— Windows Server 2022.

Research: https://www.coresecurity.com/core-labs/articles/analysis-cve-2023-28252-clfs-vulnerability

Exploit: https://github.com/duck-sec/CVE-2023-28252-Compiled-exe
👍1
Disable Windows Defender (+ UAC Bypass, + Upgrade to SYSTEM)

https://github.com/EvilGreys/Disable-Windows-Defender-
🔥4❤‍🔥1👎1
Skrapa is a zero dependency and customizable Python library for scanning Windows and Linux process memory.

https://research.nccgroup.com/2024/01/25/memory-scanning-for-the-masses/

https://github.com/fox-it/skrapa
KernelGPT: Enhanced Kernel Fuzzing via Large Language Models

https://arxiv.org/pdf/2401.00563.pdf