JMP slide: A NOP-sled alternative | Lambda driver blog
https://tin-z.github.io//intel/assembly/exploit/2023/12/12/jmp_slide.html
https://tin-z.github.io//intel/assembly/exploit/2023/12/12/jmp_slide.html
Lambda driver blog
JMP slide: A NOP-sled alternative
In the following blog post, I will introduce you to two techniques similar to NOP-sled or NOP slide, but with the advantage that they are faster. Those techniques are: JMP slide and JCC slide.
ZipLink - Combine Zips and Lnk for fun and profit | BadOption.eu
https://badoption.eu/blog/2023/09/28/ZipLink.html
https://badoption.eu/blog/2023/09/28/ZipLink.html
BadOption.eu
ZipLink - Combine Zips and Lnk for fun and profit
ZipLink - Combine Zips and Lnk for fun and profit If you look at typical exploit chains by various threat actors, lnk files still play a huge role. In this post I will share some possible chains I came up to.
GitHub - RalfHacker/Kerbeus-BOF: BOF for Kerberos abuse (an implementation of some important features of the Rubeus).
https://github.com/RalfHacker/Kerbeus-BOF
https://github.com/RalfHacker/Kerbeus-BOF
GitHub
GitHub - RalfHacker/Kerbeus-BOF: BOF for Kerberos abuse (an implementation of some important features of the Rubeus).
BOF for Kerberos abuse (an implementation of some important features of the Rubeus). - RalfHacker/Kerbeus-BOF
Detecting Direct Syscalls with Frida
https://passthehashbrowns.github.io/detecting-direct-syscalls-with-frida
https://passthehashbrowns.github.io/detecting-direct-syscalls-with-frida
From a C project, through assembly, to shellcode
https://vxug.fakedoma.in/papers/VXUG/Exclusive/FromaCprojectthroughassemblytoshellcodeHasherezade.pdf
https://vxug.fakedoma.in/papers/VXUG/Exclusive/FromaCprojectthroughassemblytoshellcodeHasherezade.pdf