Offensive Xwitter
19.3K subscribers
908 photos
48 videos
21 files
2.09K links
~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://xn--r1a.website/OffensiveTwitter/546
Download Telegram
๐Ÿ‘น [ snovvcrash, sn๐Ÿฅถvvcr๐Ÿ’ฅsh ]

[#Tooling โš”๏ธ] ๐Ÿงต (1/6) A thread of integrating #shellcode #fluctuation technique into DInjector: https://t.co/4VLQkuXO4q

Main credits to @mariuszbit, @_RastaMouse and @ShitSecure for their great tools and blogs which I heavily relied on here.

#redteam #maldev

๐Ÿ”— https://github.com/snovvcrash/DInjector/blob/0ed4182035f9dcd15cf987519e5f1320f669e962/DInjector/Modules/CurrentThread.cs#L233-L458

๐Ÿฅ [ tweet ]
๐Ÿ”ฅ3
๐Ÿ‘น [ snovvcrash, sn๐Ÿฅถvvcr๐Ÿ’ฅsh ]

[#HackTip โš’] Such a tiny code snippet that can help you bypass some automatic sandbox detections โณ

#maldev

๐Ÿฅ [ tweet ]
๐Ÿ‘น [ snovvcrash, sn๐Ÿฅถvvcr๐Ÿ’ฅsh ]

[#Tooling โš”๏ธ] Updated my SharpBin2SelfInject gist with the recent H/Invoke technique by @dr4k0nia for a stealthier GetModuleHandle / GetProcAddress resolution and invocation ๐Ÿฅท๐Ÿป

https://t.co/JZd3YCXfPh

#maldev #dinvoke #hinvoke

๐Ÿ”— https://gist.github.com/snovvcrash/30bd25b1a5a18d8bb7ce3bb8dc2bae37

๐Ÿฅ [ tweet ]
๐Ÿ˜ˆ [ CaptMeelo, Meelo ]

Got some time over the weekend to make a new post. Here you go.
#redteam #maldev #pentest

https://t.co/Qlyc6A7YEf

๐Ÿ”— https://captmeelo.com/redteam/maldev/2022/10/17/independent-malware.html

๐Ÿฅ [ tweet ]
๐Ÿ˜ˆ [ CaptMeelo, Meelo ]

I made some experiments over the past few days and I wanted share what I learned/observed.
#redteam #maldev #infosec
https://t.co/l1ANZbf6fg

๐Ÿ”— https://captmeelo.com/redteam/maldev/2022/11/07/cloning-signing.html

๐Ÿฅ [ tweet ]
๐Ÿ˜ˆ [ CaptMeelo, Meelo ]

Here's the tool that I demoed during my #SANSHackFest talk. Let's make it better by filing any issues you identified and submitting PRs.
#redteam #maldev
https://t.co/KvCJzVwSxi

๐Ÿ”— https://github.com/capt-meelo/laZzzy

๐Ÿฅ [ tweet ]
๐Ÿ‘น [ snovvcrash, sn๐Ÿฅถvvcr๐Ÿ’ฅsh ]

(1/2) Despite being busy on an RT engagement, Iโ€™ve also played with the NtCreateUserProcess PoC in C# and if youโ€™ve troubles with spawning the proc, you wanna take a closer look at the attributeList.TotalLength value.

#maldev

๐Ÿฅ [ tweet ][ quote ]
๐Ÿ˜ˆ [ _atsika, Atsika ]

I've just started a blog on #maldev and #redteaming. Nothing fancy yet, just me trying to see if I've understood correctly.
The first post is about a custom version of GetModuleHandle and GetProcAddress in #go.
Check it out:

๐Ÿ”— https://blog.atsika.ninja/posts/custom_getmodulehandle_getprocaddress/

๐Ÿฅ [ tweet ]
๐Ÿ”ฅ2
Forwarded from APT
๐Ÿ‘ฉโ€๐Ÿ’ป Writing your own RDI /sRDI loader using C and ASM

Learn the process of crafting a personalized RDI/sRDI loader in C and ASM, incorporating code optimization to achieve full position independence.

๐Ÿ”— https://blog.malicious.group/writing-your-own-rdi-srdi-loader-using-c-and-asm/

#maldev #reflective #dll #clang #asm
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘5