π [ markrussinovich, Mark Russinovich ]
Check out my Microsoft Build interview with @sethjuarez on Azure Container Apps + Dapr, a big step in the evolution of serverless: https://t.co/mqla60UZFz
π https://www.youtube.com/watch?v=dplT6YL66Mg
π₯ [ tweet ]
Check out my Microsoft Build interview with @sethjuarez on Azure Container Apps + Dapr, a big step in the evolution of serverless: https://t.co/mqla60UZFz
π https://www.youtube.com/watch?v=dplT6YL66Mg
π₯ [ tweet ]
π [DirectoryRanger, DirectoryRanger]
ADeleg. Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest, along with their potential issues
https://t.co/sbqcK2mPHW
π https://github.com/mtth-bfft/adeleg
π₯ [tweet]
ADeleg. Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest, along with their potential issues
https://t.co/sbqcK2mPHW
π https://github.com/mtth-bfft/adeleg
π₯ [tweet]
π [DirectoryRanger, DirectoryRanger]
Offensive Windows IPC Internals, by @0xcsandker
Part 1: Named Pipes https://t.co/Ug3gPKZANi
Part 2: RPC https://t.co/cfgY8dTLTa
Part 3: ALPC https://t.co/avXPjhqml4
π https://csandker.io/2021/01/10/Offensive-Windows-IPC-1-NamedPipes.html
π https://csandker.io/2021/02/21/Offensive-Windows-IPC-2-RPC.html
π https://csandker.io/2022/05/24/Offensive-Windows-IPC-3-ALPC.html
π₯ [tweet]
Offensive Windows IPC Internals, by @0xcsandker
Part 1: Named Pipes https://t.co/Ug3gPKZANi
Part 2: RPC https://t.co/cfgY8dTLTa
Part 3: ALPC https://t.co/avXPjhqml4
π https://csandker.io/2021/01/10/Offensive-Windows-IPC-1-NamedPipes.html
π https://csandker.io/2021/02/21/Offensive-Windows-IPC-2-RPC.html
π https://csandker.io/2022/05/24/Offensive-Windows-IPC-3-ALPC.html
π₯ [tweet]
π [DirectoryRanger, DirectoryRanger]
Hunting for Active Directory Certificate Services Abuse, by @HeirhabarovT
https://t.co/adwuv53TOL
π https://speakerdeck.com/heirhabarov/hunting-for-active-directory-certificate-services-abuse
π₯ [tweet]
Hunting for Active Directory Certificate Services Abuse, by @HeirhabarovT
https://t.co/adwuv53TOL
π https://speakerdeck.com/heirhabarov/hunting-for-active-directory-certificate-services-abuse
π₯ [tweet]
π [cyb3rops, Florian Roth π]
Remember, when you write #YARA rules for RTF files that "{\rtf" isnβt the header that you should look for, since the βfβ isnβt required by Microsoft Word to open the file
Better use:
uint32be(0) == 0x7B5C7274
which is "{\rt" at position 0
https://t.co/vzBbEcZJd1
π https://furoner.wordpress.com/2017/07/06/analysis-of-new-rtf-malware-obfuscation-method/
π₯ [tweet]
Remember, when you write #YARA rules for RTF files that "{\rtf" isnβt the header that you should look for, since the βfβ isnβt required by Microsoft Word to open the file
Better use:
uint32be(0) == 0x7B5C7274
which is "{\rt" at position 0
https://t.co/vzBbEcZJd1
π https://furoner.wordpress.com/2017/07/06/analysis-of-new-rtf-malware-obfuscation-method/
π₯ [tweet]