Forwarded from Sec Note
🔓 Dumping NTLM Hashes from Windows Memory via forensics tools
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
#RedTeam #OffensiveSecurity
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM
#RedTeam #OffensiveSecurity
💘5👍2
XSS_Private_Messages.rar
2 MB
credits : Dancho Danchev
🥰9💘1
Source Byte
https://github.com/FSECDEV/LEAKSFORUMS/blob/main/README.md
This media is not supported in your browser
VIEW IN TELEGRAM
💅4
Forwarded from Sec Note
This media is not supported in your browser
VIEW IN TELEGRAM
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
💅4👎3🥰1
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF
#CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023. However, Nebula Security discovered a bypass of the patch and found that it is actually exploitable and can lead to LPE on any Linux distribution that has IPv6 and namespaces enabled. This writeup covers the technical details of the exploit.
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023. However, Nebula Security discovered a bypass of the patch and found that it is actually exploitable and can lead to LPE on any Linux distribution that has IPv6 and namespaces enabled. This writeup covers the technical details of the exploit.
https://nebusec.ai/research/cve-2026-43501-route-of-root/
👾2
Source Byte
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF #CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023.…
cool platform, don' miss it :)
👍6😈1
https://x.com/WuBlockchain/status/2090396627257503764
How the Tornado Cash Lawsuit Was Won and Why It Matters
https://youtu.be/4BfiRMGs6Hg?si=mu3-IyMMcFLK61Jq
How the Tornado Cash Lawsuit Was Won and Why It Matters
https://youtu.be/4BfiRMGs6Hg?si=mu3-IyMMcFLK61Jq
👍4
Building Something EDR-like with Rust×eBPF
https://speakerdeck.com/sunlife3/rustxebpf-de-edr-ppoi-mono-o-tsukuru
https://speakerdeck.com/sunlife3/rustxebpf-de-edr-ppoi-mono-o-tsukuru
💘3
We were able to identify 6 Iran related underground activity , but yet shared POC of "JumpJump" vpn incident is unknown to us. It will be very helpful to help us cluster this activity by sending more details in our channel DM :)
also you don't need to pay for VPN !!!
Unredacted group provide high quality free solutions to anyone who need free access to internet :)
Try it now :
https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/
also you don't need to pay for VPN !!!
Unredacted group provide high quality free solutions to anyone who need free access to internet :)
Try it now :
https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/
💘31🥰9😈1
Forwarded from Sec Note
My New Blog Post
Evading Sysmon Dns Monitoring In 2026 | binary-win
DNSevade : https://github.com/binary-win/DNSevade.git
#sysmon #bypass
Your Notes are HERE
Evading Sysmon Dns Monitoring In 2026 | binary-win
DNSevade : https://github.com/binary-win/DNSevade.git
Sysmon gets its DNS telemetry from theMicrosoft-Windows-DNS-ClientETW provider.
Let's hide in plain sight.
#sysmon #bypass
Your Notes are HERE
😈3