Ryuk’s Return https://thedfirreport.com/2020/10/08/ryuks-return/
The DFIR Report
Ryuk's Return - The DFIR Report
Intro The Ryuk group went from an email to domain wide ransomware in 29 hours and asked for over $6 million to unlock our systems. They used tools such as Cobalt Strike, AdFind, WMI, vsftpd, PowerShell, PowerView, and Rubeus to accomplish their objective.…
Security Analysis of CHERI ISA https://github.com/microsoft/MSRC-Security-Research/blob/master/papers/2020/Security%20analysis%20of%20CHERI%20ISA.pdf
GitHub
MSRC-Security-Research/Security analysis of CHERI ISA.pdf at master · microsoft/MSRC-Security-Research
Security Research from the Microsoft Security Response Center (MSRC) - MSRC-Security-Research/Security analysis of CHERI ISA.pdf at master · microsoft/MSRC-Security-Research
Droppers, Downloaders and TrickBot: Detecting a Stealthy COVID-19-themed Campaign using Toolmarks https://threatresearch.ext.hp.com/detecting-a-stealthy-trickbot-campaign/
Bromium
Droppers, Downloaders and TrickBot: Detecting a Stealthy COVID-19-themed Campaign using Toolmarks - Bromium
In September 2020, TrickBot's operators launched a malicious spam campaign that was effective at evading detection. Read about the techniques they used.
Building an Obfuscator to Evade Windows Defender https://www.xanthus.io/post/building-an-obfuscator-to-evade-windows-defender
Xanthus
Building an Obfuscator to Evade Windows Defender - Xanthus
Introduction Any redteamer working in a windows enterprise environment will eventually have to cross paths with Windows Defender and its anti-malware competent AMSI. For an operator the inability to drop the proper tools during an engagement can be very frustrating…
Methodology for Static Reverse Engineering of Windows Kernel Drivers https://posts.specterops.io/methodology-for-static-reverse-engineering-of-windows-kernel-drivers-3115b2efed83
SpecterOps
Blog - SpecterOps
Your new best friend: Introducing BloodHound Community Edition!
CVE-2019-0230: Apache Struts OGNL Remote Code Execution https://www.zerodayinitiative.com/blog/2020/10/7/cve-2019-0230-apache-struts-ognl-remote-code-execution
Zero Day Initiative
Zero Day Initiative — CVE-2019-0230: Apache Struts OGNL Remote Code Execution
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Kc Udonsi and John Simpson of the Trend Micro Research Team detail a recent code execution vulnerability in the Apache Struts framework. The bug was originally discovered…
nice post --> A Deep Dive Into RUNDLL32.EXE https://medium.com/@nasbench/a-deep-dive-into-rundll32-exe-642344b41e90
Medium
A Deep Dive Into RUNDLL32.EXE
Understanding “rundll32.exe” command line arguments
How To Unpack Malware: Personal Notes https://marcoramilli.com/2020/10/09/how-to-unpack-malware-personal-notes/
We Hacked Apple for 3 Months: Here’s What We Found https://samcurry.net/hacking-apple/
samcurry.net
We Hacked Apple for 3 Months: Here’s What We Found
Between the period of July 6th to October 6th myself, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes worked together and hacked on the Apple bug bounty program.
Zero-day in Sign in with Apple https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/
NTLMRawUnHide: parse network packet capture files and extract NTLMv2 hashes https://securityonline.info/ntlmrawunhide/
Penetration Testing
NTLMRawUnHide: parse network packet capture files and extract NTLMv2 hashes
NTLMRawUnHide was developed to extract NTLMv2 hashes from files generated by native Windows binaries like NETSH.EXE and PKTMON.EXE without conversion.
Acronis backup software contains multiple privilege escalation vulnerabilities https://kb.cert.org/vuls/id/114757
www.kb.cert.org
CERT/CC Vulnerability Note VU#114757
Acronis backup software contains multiple privilege escalation vulnerabilities
Really nice post! » Low-level Reversing of SIGred (CVE-2020–1350), by @ricnar456 https://www.coresecurity.com/core-labs/articles/low-level-reversing-sigred-cve-2020-1350
Coresecurity
Low-level Reversing of SIGred (CVE-2020–1350) | Core Labs Articles| Core Security
Explore how the SIGred (CVE-2020-1350) vulnerability can exploited.
Microsoft SharePoint Server DataFormWebPart CreateChildControls Server-Side Include Remote Code Execution Vulnerability https://srcincite.io/pocs/cve-2020-16952.py.txt
Mastering 4 Stages of Malware Analysis https://zeltser.com/mastering-4-stages-of-malware-analysis/
Lenny Zeltser
Mastering 4 Stages of Malware Analysis
Malware analysis techniques form a pyramid of increasing complexity: fully-automated analysis, static properties examination, interactive behavioral analysis, and manual code reversing. Analysts typically combine these stages iteratively, with insights from…
Morty Sherlocked: Android Application Based CTF Challenge Walkthrough https://medium.com/swlh/morty-sherlocked-android-application-ctf-challenge-walkthrough-ab1ec2161cb4
Medium
Morty Sherlocked: Android Application Based CTF Challenge Walkthrough
Morty Sherlocked is a beginner level Android application CTF challenge. It walks us through the basic concepts of Android application…
You should update immediately your iOS device >> https://thehackernews.com/2020/11/update-your-ios-devices-now-3-actively.html
OceanLotus Old techniques, new backdoor https://www.welivesecurity.com/wp-content/uploads/2018/03/ESET_OceanLotus.pdf
nice talk on BH Asia20 >> Finding Backdoors in Applications https://i.blackhat.com/asia-20/Friday/asia-20-Loke-Patching-Loopholes-Finding-Backdoors-In-Applications.pdf