Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @Oddvarmoe
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @Oddvarmoe
-
Pinned Tweet
CVE 2017-8625 is out. Me proud? Oh yeah! Lifetime goal achieved. https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8625 … -
#MyFirstCVE#DeviceGuardByPass@enigma0x3pic.twitter.com/topjJ0TDI6
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
How sure are you that "(Verified) Microsoft Windows" refers to a program that actually originates from Microsoft? Code Signing Certificate Cloning Attacks and Defenseshttps://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec …
Thanks. Twitter will use this to make your timeline better. Undo -
AppLocker case study blogposts so far. More to come! AppLocker study 1 - https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/ … AppLocker study 2 - https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/ … Hardening based on study 1 - https://oddvar.moe/2017/12/13/harden-windows-with-applocker-based-on-case-study-part-1/ … Hardening based on study 2 - https://oddvar.moe/2017/12/21/harden-windows-with-applocker-based-on-case-study-part-2/ …
#AppLocker#FeedBackWelcomepic.twitter.com/XVnX69CpAWThanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
I have a metasploit module to test some of the bypasses you mention. Here is a link to the pull request if you are interestedhttps://github.com/rapid7/metasploit-framework/pull/8783 …
Thanks. Twitter will use this to make your timeline better. Undo -
Harden Windows with AppLocker - Part 2 of my hardening posts - https://oddvar.moe/2017/12/21/harden-windows-with-applocker-based-on-case-study-part-2/ …
#FeedBackWelcome#AppLocker#Hardeningpic.twitter.com/4QJg0BksCtThanks. Twitter will use this to make your timeline better. Undo -
Another blogpost about my case study on AppLocker bypasses - Part 2 - https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/ … - I could use some coding help from someone to verify 2 of the bypasses.
#FeedBackWelcome#AppLockerpic.twitter.com/VbgOy4vjDeThanks. Twitter will use this to make your timeline better. Undo -
Writing part 2 of my blog series "AppLocker - How insecure is it really?" - Just realized that .PS1 is no longer blocked by AppLocker, but rather depends on constrained language mode in PowerShell. Hopefully the blogpost will be done by tomorrow. Part 1 -https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/ …
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
The wait is over! Registration for
#BlueHatIL 2018 is now open. Places are limited so register today! http://Bluehatil.com pic.twitter.com/pfVRrlLOQM
Thanks. Twitter will use this to make your timeline better. Undo -
I got mixed feelings about this: https://mdb-dev.es/2017/12/20/dont-let-an-auto-elevating-bot-spoil-your-christmas/ … My research on CMSTP.exe and
@hFireF0X awesome code is used as part of an auto elevating bot. I feel kind of honored and at the same time it feels very wrong. Anyways, great blogpost.pic.twitter.com/pSOtfN1aVuThanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
My "scrap" or junk code as an experiment. This was me writing a quick PoC hook to grab TLS Req/Resp from PowerShell memory, instead of with a proxy https://github.com/caseysmithrc/memMITM … Take a look, experimental PoC only. May be helpful/interesting. Feedback Welcome. Still more to do...
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
ICYMI, Check out
@Cyb3rWard0g's take on Data Quality for Threat Hunting!https://twitter.com/Cyb3rWard0g/status/941818396508766208 …Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
DLL/Exe execution via Tracker.exe (Microsoft signed binary, part of Visual Studio) .\Tracker.exe /d .\calc.dll /c C:\Windows\write.exe Can be used outside of Visual Studio, needs a DLL "TrackerUI.dll" (again from VIsual Studio) present in a subfolder "1028"pic.twitter.com/mt21fcYJEK
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
@Oddvarmoe I know you’ll appreciate this. A meme our Helpdesk created when something was broken with CM.
pic.twitter.com/89ufCtOPHa
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
DNSTrails The World's Largest Repository of historical DNS data https://dnstrails.com/#/ pic.twitter.com/IhTfcY0nEu
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
Oh Wow, this was a blast to write. In Memory SSL Intercept ;-). Thanks again mavinject! All your Encrypted PowerShell WebRequests Are Belong To Us ;-) https://gist.github.com/anonymous/00c281d0dd4aa5af5b4e6027f2dd706b … Have Fun!pic.twitter.com/TFvaQtb2Ad
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
Simple DLL Inject UserMode Hook Example: https://gist.github.com/anonymous/b25cb82c4b3d40648f0b589fa242577f … Nice Complimentary pairing with mavinject.exe
In this example, we hook CreateProcess and prevent cmd.exe/taskmgr.exe
PoC only, but you get the idea.
More interesting would be to hook sspicli!EncryptMessage ;-)pic.twitter.com/qeSIUba24V
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
[New Post] Microsoft Office – NTLM Hashes via Frameset https://pentestlab.blog/2017/12/18/microsoft-office-ntlm-hashes-via-frameset/ …
#pentestlab#RedTeam#pentestingThanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
I created a new Windows 10 VM with a pristine image from MSDN, and noticed a third party password manager is now installed by default. It didn't take long to find a critical vulnerability. https://bugs.chromium.org/p/project-zero/issues/detail?id=1481 …
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
Not all DLLs are created equally. Learn the basics of the Windows architecture.https://hubs.ly/H09qBgS0
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
New Blog Post: Use
#SCCM#ConfigMgr to bypass Device Guard / Applocker https://master-client.com/sccm-bypass-applocker/ …pic.twitter.com/pWhWOcVSB0
Thanks. Twitter will use this to make your timeline better. Undo -
Oddvar Moe [MVP] Retweeted
[New Post] Microsoft Office – Payloads in Document Properties https://pentestlab.blog/2017/12/15/microsoft-office-payloads-in-document-properties/ …
#pentestlab#redteamThanks. Twitter will use this to make your timeline better. Undo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.