π [ Gigel Vrancea @GigelV41464 ]
Someone on my team asked me if there was a way I could prevent in-proc tools like a BOF from crashing the process
After some research, I came to the conclusion that using RtlSetUnhandledExceptionFilter is the most elegant way to achieve this
Read here:
π https://luci4.net/blog/2024/11/13/EternalLife/
π₯ [ tweet ]
Someone on my team asked me if there was a way I could prevent in-proc tools like a BOF from crashing the process
After some research, I came to the conclusion that using RtlSetUnhandledExceptionFilter is the most elegant way to achieve this
Read here:
π https://luci4.net/blog/2024/11/13/EternalLife/
π₯ [ tweet ]
π3
π [ Volexity @Volexity ]
@Volexityβs latest blog post describes in detail how a Russian APT used a new attack technique, the βNearest Neighbor Attackβ, to leverage Wi-Fi networks in close proximity to the intended target, while the attacker was halfway around the world.
π https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
π₯ [ tweet ]
@Volexityβs latest blog post describes in detail how a Russian APT used a new attack technique, the βNearest Neighbor Attackβ, to leverage Wi-Fi networks in close proximity to the intended target, while the attacker was halfway around the world.
π https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
π₯ [ tweet ]
ΠΏΠΎΠ·Π½Π°Π²Π°ΡΠ΅Π»ΡΠ½ΠΎπ6π₯3
π [ Yehuda Smirnov @yudasm_ ]
Excited to share a tool I've been working on - ShadowHound.
ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them:
Blog:
π https://blog.fndsec.net/2024/11/25/shadowhound/
Code:
π https://github.com/Friends-Security/ShadowHound
π₯ [ tweet ]
Excited to share a tool I've been working on - ShadowHound.
ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them:
Blog:
π https://blog.fndsec.net/2024/11/25/shadowhound/
Code:
π https://github.com/Friends-Security/ShadowHound
π₯ [ tweet ]
π8
π [ PT SWARM @ptswarm ]
π€β¨ Our security researcher, Konstantin Polishin, presented βRed Team Social Engineering 2024: Initial Access TTP and Project Experience of Our Teamβ at #ROOTCON18 π
Recording:
π https://youtube.com/watch?v=6nnZJiL0Tgk
π₯ [ tweet ]
π€β¨ Our security researcher, Konstantin Polishin, presented βRed Team Social Engineering 2024: Initial Access TTP and Project Experience of Our Teamβ at #ROOTCON18 π
Recording:
π https://youtube.com/watch?v=6nnZJiL0Tgk
π₯ [ tweet ]
π₯8
π [ ap @decoder_it ]
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub:
π https://github.com/decoder-it/KrbRelayEx
π₯ [ tweet ]
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub:
π https://github.com/decoder-it/KrbRelayEx
π₯ [ tweet ]
π12
π [ RedTeam Pentesting @RedTeamPT ]
So we implemented parsing the security descriptors of shares and files in the beautiful β¨smbclient-ng β¨ by @podalirius_
Here is our PR:
π https://github.com/p0dalirius/smbclient-ng/pull/118
π₯ [ tweet ][ reply ]
So we implemented parsing the security descriptors of shares and files in the beautiful β¨smbclient-ng β¨ by @podalirius_
Here is our PR:
π https://github.com/p0dalirius/smbclient-ng/pull/118
π₯ [ tweet ][ reply ]
π9π₯3
π [ Check Point Research @_CPResearch_ ]
π¨ New Discovery! We uncovered an undocumented technique for executing commands through the #Godot #GameEngine. Exploited by #GodLoader, this method successfully bypassed most #antivirus software since June 2024, affecting over 17,000 potential victims.
π https://research.checkpoint.com/2024/gaming-engines-an-undetected-playground-for-malware-loaders/
π₯ [ tweet ]
π¨ New Discovery! We uncovered an undocumented technique for executing commands through the #Godot #GameEngine. Exploited by #GodLoader, this method successfully bypassed most #antivirus software since June 2024, affecting over 17,000 potential victims.
π https://research.checkpoint.com/2024/gaming-engines-an-undetected-playground-for-malware-loaders/
π₯ [ tweet ]
π3π₯1
π [ S3cur3Th1sSh1t @ShitSecure ]
Seven days ago @prac_sec released a blog post about Patching CLR memory to bypass AMSI. This is now added to the AMSI Bypass Powershell repo as well:
π https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell/tree/master?tab=readme-ov-file#Patching-Clr
π https://practicalsecurityanalytics.com/new-amsi-bypss-technique-modifying-clr-dll-in-memory/
π₯ [ tweet ]
Seven days ago @prac_sec released a blog post about Patching CLR memory to bypass AMSI. This is now added to the AMSI Bypass Powershell repo as well:
π https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell/tree/master?tab=readme-ov-file#Patching-Clr
π https://practicalsecurityanalytics.com/new-amsi-bypss-technique-modifying-clr-dll-in-memory/
π₯ [ tweet ]
π9π₯3
π [ Layle @layle_ctf ]
In a somewhat recent project we used a vulnerable driver, which worked fine...
Except: The customer had a custom rule that caused an alert when a service is created!
Decided to write a tool that creates the registry keys and calls into NtLoadDriver:
π https://github.com/ioncodes/SilentLoad
π₯ [ tweet ]
In a somewhat recent project we used a vulnerable driver, which worked fine...
Except: The customer had a custom rule that caused an alert when a service is created!
Decided to write a tool that creates the registry keys and calls into NtLoadDriver:
π https://github.com/ioncodes/SilentLoad
π₯ [ tweet ]
π1
π [ drm @lowercase_drm ]
Coffee break thoughts: "is it possible to bruteforce RPC endpoint to perform code exec if you can't access EPM/SMB?"
99% impacket atexec + 1% "for loop" = 100% prod ready
(silent command only)
h/t @saerxcit
π»
π https://gist.github.com/ThePirateWhoSmellsOfSunflowers/3673746454aef7d55a5efed4dc4e1a61
π₯ [ tweet ]
Coffee break thoughts: "is it possible to bruteforce RPC endpoint to perform code exec if you can't access EPM/SMB?"
99% impacket atexec + 1% "for loop" = 100% prod ready
(silent command only)
h/t @saerxcit
π»
π https://gist.github.com/ThePirateWhoSmellsOfSunflowers/3673746454aef7d55a5efed4dc4e1a61
π₯ [ tweet ]
π₯3
π [ Mayfly @M4yFly ]
Goad v3 merged into the main branch π₯³
GitHub:
π https://github.com/Orange-Cyberdefense/GOAD
Doc:
π https://orange-cyberdefense.github.io/GOAD/
π₯ [ tweet ]
Goad v3 merged into the main branch π₯³
GitHub:
π https://github.com/Orange-Cyberdefense/GOAD
Doc:
π https://orange-cyberdefense.github.io/GOAD/
π₯ [ tweet ]
π9π’1
π [ blueblue @piedpiper1616 ]
GitHub - TheN00bBuilder/cve-2024-11477-writeup: CVE-2024-11477 7Zip Code Execution Writeup and Analysis
π https://github.com/TheN00bBuilder/cve-2024-11477-writeup
π₯ [ tweet ]
GitHub - TheN00bBuilder/cve-2024-11477-writeup: CVE-2024-11477 7Zip Code Execution Writeup and Analysis
π https://github.com/TheN00bBuilder/cve-2024-11477-writeup
π₯ [ tweet ]
π4
π [ Rasta Mouse @_RastaMouse ]
[BLOG]
This post summarises how to tie Cobalt Strike's UDRL, SleepMask, and BeaconGate together for your syscall and call stack spoofing needs.
π https://rastamouse.me/udrl-sleepmask-and-beacongate/
π₯ [ tweet ]
[BLOG]
This post summarises how to tie Cobalt Strike's UDRL, SleepMask, and BeaconGate together for your syscall and call stack spoofing needs.
π https://rastamouse.me/udrl-sleepmask-and-beacongate/
π₯ [ tweet ]
π€1
π [ Fabian Bader @fabian_bader ]
π‘οΈWindows Firewall and WFP are only two ways to silence an #EDR agent.
π’In my latest blog post I discuss another network based technique to prevent data ingest and ways to detect it.
π https://cloudbrothers.info/en/edr-silencers-exploring-methods-block-edr-communication-part-1/
And if you want even more, checkout part 2 released by @Cyb3rMonk
π₯ [ tweet ]
π‘οΈWindows Firewall and WFP are only two ways to silence an #EDR agent.
π’In my latest blog post I discuss another network based technique to prevent data ingest and ways to detect it.
π https://cloudbrothers.info/en/edr-silencers-exploring-methods-block-edr-communication-part-1/
And if you want even more, checkout part 2 released by @Cyb3rMonk
π₯ [ tweet ]
π₯4π1
π [ Check Point Research @_CPResearch_ ]
A ransomware gang's Rust experiment naturally produced the kind of binary you "reverse-engineer" by staring at the strings and saying, "mm hm." Join us as we break through this technical barrier and gain some insight into ransomware author psychology.
π https://research.checkpoint.com/2024/inside-akira-ransomwares-rust-experiment/
π₯ [ tweet ]
A ransomware gang's Rust experiment naturally produced the kind of binary you "reverse-engineer" by staring at the strings and saying, "mm hm." Join us as we break through this technical barrier and gain some insight into ransomware author psychology.
π https://research.checkpoint.com/2024/inside-akira-ransomwares-rust-experiment/
π₯ [ tweet ]
π2
π [ MDSec @MDSecLabs ]
Ever come across Altiris on a red team? We did.... Check out this post from @breakfix on how to extract ACC creds... Extracting Account Connectivity Credentials (ACCs) from Symantec Management Agent (aka Altiris)
π https://www.mdsec.co.uk/2024/12/extracting-account-connectivity-credentials-accs-from-symantec-management-agent-aka-altiris/
π₯ [ tweet ]
Ever come across Altiris on a red team? We did.... Check out this post from @breakfix on how to extract ACC creds... Extracting Account Connectivity Credentials (ACCs) from Symantec Management Agent (aka Altiris)
π https://www.mdsec.co.uk/2024/12/extracting-account-connectivity-credentials-accs-from-symantec-management-agent-aka-altiris/
π₯ [ tweet ]
π2π2
π [ Ricardo Ruiz @RicardoJoseRF ]
Today I made public NativeBypassCredGuard, a tool to bypass Credential Guard by patching WDigest.dll using only NTAPI functions:
π https://github.com/ricardojoserf/NativeBypassCredGuard
π₯ [ tweet ]
Today I made public NativeBypassCredGuard, a tool to bypass Credential Guard by patching WDigest.dll using only NTAPI functions:
π https://github.com/ricardojoserf/NativeBypassCredGuard
π₯ [ tweet ]
π12
π [ S3cur3Th1sSh1t @ShitSecure ]
Finally I was finally able to reproduce RemotePotat0 from @splinter_code and @decoder_it which still works perfectly fine when relaying against SMB and choosing the correct CLSID :-) Only LDAP relaying it patched and not possible anymore.
Super late but Β―\_(γ)_/ Β― π€ͺ
But you know what's even better? KrbRelay also works from a low privileged users perspective! π₯π₯π₯
π₯ [ tweet ][ quote ]
Finally I was finally able to reproduce RemotePotat0 from @splinter_code and @decoder_it which still works perfectly fine when relaying against SMB and choosing the correct CLSID :-) Only LDAP relaying it patched and not possible anymore.
Super late but Β―\_(γ)_/ Β― π€ͺ
But you know what's even better? KrbRelay also works from a low privileged users perspective! π₯π₯π₯
π₯ [ tweet ][ quote ]
π₯7π4π€―1