just because you can put anything in containers
doesn't mean you should put everything in containers
doesn't mean you should put everything in containers
parse #formbook PCAPs containing HTTP requests to C&C.extracting: * Beaconing requests * Intercepted HTML forms * Password Recoveries * Clipboard data * Screenshot
https://bit.ly/2Czyy8c
https://bit.ly/2Czyy8c
Active Directory Assessment and Privilege Escalation Script
https://github.com/hausec/ADAPE-Script/tree/master
https://github.com/hausec/ADAPE-Script/tree/master
pypykatz
Mimikatz implementation in pure Python. -offline minidump parsing currently-
Runs on all OS's which support python>=3.6
https://github.com/skelsec/pypykatz
Mimikatz implementation in pure Python. -offline minidump parsing currently-
Runs on all OS's which support python>=3.6
https://github.com/skelsec/pypykatz
GitHub
GitHub - skelsec/pypykatz: Mimikatz implementation in pure Python
Mimikatz implementation in pure Python. Contribute to skelsec/pypykatz development by creating an account on GitHub.
Top 10 Web Hacking Techniques of 2017
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
PortSwigger Research
Top 10 Web Hacking Techniques of 2017
The verdict is in! Following 37 nominations whittled down to a shortlist of 15 by a community vote, our panel of experts has conferred and selected the top 10 web hacking techniques of 2017 (and 2016)
Extending Burp to Find Struts and XXE Vulnerabilities
https://www.irongeek.com/i.php?page=videos/derbycon8/stable-21-extending-burp-to-find-struts-and-xxe-vulnerabilities-chris-elgee
https://www.irongeek.com/i.php?page=videos/derbycon8/stable-21-extending-burp-to-find-struts-and-xxe-vulnerabilities-chris-elgee
Irongeek
Extending Burp to Find Struts and XXE Vulnerabilities - Chris Elgee Derbycon 2018 (Hacking Illustrated Series InfoSec Tutorial…
Irongeek's Information Security site with tutorials, articles and other information.
Windows oneliners to download remote payload and execute arbitrary code
https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/
https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/
arno0x0x
Windows oneliners to download remote payload and execute arbitrary code
In the wake of the recent buzz and trend in using DDE for executing arbitrary command lines and eventually compromising a system, I asked myself « what are the coolest command lines an a…