Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ReleasePreview
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ReleasePreview
-
Alexander Fischer proslijedio/la je Tweet
Can your EDR detect symbolic link callback rootkits? Because ours sure as heck can't.
@aionescu and I wrote about these! https://windows-internals.com/dkom-now-with-symbolic-links/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Windows / Linux Local Privilege Escalation Workshop (Materials included !)
https://github.com/sagishahar/lpeworkshop …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Microsoft have released an open source tool to analyze source code for vulnerabilities in almost any modern language:https://github.com/Microsoft/ApplicationInspector/wiki …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Here is the link to the SpecterOps Adversary Tactics: PowerShell course material: https://github.com/specterops/at-ps … Enjoy! For information about our current training offerings, information can be found here: https://specterops.io/how-we-help/training-offerings … (4/4)
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Oh nice, RCE in Internet Explorer: https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001 … ... good timing with the ECC bug. Also anyone requiring users to use IE to access Citrix?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
If you’re tired of hearing about crypto32, elliptic curves, and other CVE-2020-0601 shenanigans, have a read over our new blog post on Windows’ Intel CET implementation in the face of SetThreadContext and NtContinue. Come for the exploit mitigation, stay for the XState Internals. https://twitter.com/yarden_shafir/status/1217728223355817986 …pic.twitter.com/rfFlA1aZXR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Hey, new upload to Windows-Insight - the Windows Telemetry ETW Monitor framework: https://github.com/ernw/Windows-Insight/tree/master/files/wintel_etwmonitor … The framework monitors and reports on ETW (Event Tracing for Windows) activities for providing data to Windows Telemetry. Works on Windows 10, version 1909. [Thread: 1/4]
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
#Citrix#Netscaler#Shitrix
Snort
https://doc.emergingthreats.net/bin/view/Main/2029206 …
Sigma
https://github.com/Neo23x0/sigma/blob/master/rules/web/web_citrix_cve_2019_19781_exploit.yml …
YARA
https://github.com/Neo23x0/signature-base/blob/master/yara/exploit_shitrix.yar …
IOCs
https://otx.alienvault.com/pulse/5e1c293e07c770f36d232489 …
Nmap NSE
https://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2019-19781/CVE-2019-19781.nse …
MSF
https://github.com/rapid7/metasploit-framework/blob/a64b0fa9e75befc3ffdb6129e88a6f6dd4c31208/modules/exploits/unix/webapp/citrix_dir_trasversal_rce.rb …
HoneyPot
https://github.com/MalwareTech/CitrixHoneypot …
SSH checkhttps://twitter.com/cyb3rops/status/1216310642552049666 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Check our new post: APT27 ZxShell RootKit module updates https://lab52.io/blog/apt27-rootkit-updates/ …
#malware#APTHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
1. I worked with Anna Zaitsev (Berkely postdoc) to study YouTube recommendation radicalization. We painstakingly collected and grouped channels (768) and recommendations (23M) and found that the algo has a deradicalizing influence. Pre-print: https://arxiv.org/abs/1912.11211
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
SharpSploit v1.5 is out! Includes amazing work from
@_RastaMouse,@checkymander,@001SPARTaN,@FuzzySec, and@TheRealWover. Includes: lateral movement over SCM and PSRemoting, an AMSI bypass, CreateProcessWithToken, and DynamicInvoke improvements.

https://github.com/cobbr/SharpSploit …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Sigma2Attack generates
#MITRE ATT&CK navigator heat maps from a set of#sigma rules by@christophetd Pull Request - already merged into master https://github.com/Neo23x0/sigma/pull/566 … ATT&CK Navigator https://mitre-attack.github.io/attack-navigator/enterprise/ …pic.twitter.com/jOL2eDgcKO
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Christmas came earlier this year, fresh new release of timesketch with big improvements and fancy new ui!https://github.com/google/timesketch/releases/tag/20191220 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Finally: Malwoverview 2.0 (in Python 3.x) is available! https://github.com/alexandreborges/malwoverview … There're so many news, so it's better to check on the GitHub ;)
#malware#threatintelligence#threathunting#securitypic.twitter.com/SkDU89PZsN
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Learn how to exploit Symantec Endpoint Protection on all versions of Windows (CVE-2019-12750). Part 2 of this series by
@kyREcon delves into a more advanced method of exploitation!https://labs.nettitude.com/blog/cve-2019-12750-symantec-endpoint-protection-local-privilege-escalation-part-2/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
[New blog] Updating adconnectdump - a journey into DPAPI; In which I describe the process of understanding and decrypting the DPAPI encrypted credentials of Azure AD connect. This again enables dumping these credentials via only network calls (as admin). https://dirkjanm.io/updating-adconnectdump-a-journey-into-dpapi/ …pic.twitter.com/H6yZwjAFtA
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Introducing SysWhispers, a tool that helps with AV/EDR evasion by using direct system calls to bypass user-mode API hooks. It works by generating header/ASM pairs supporting all core syscalls from Windows XP to 10. Check it out here with examples:https://github.com/jthuraisamy/SysWhispers …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
After stumbling upon c:\windows\system32\runexehelper.exe and some reversing I figured out it can be used to run execs (two conditions: diagtrack_action_output env var needs to be set to a writable directory and runexewithargs_output.txt must not exist there).
#LOLBas#LOLBinpic.twitter.com/T9tlfA4J7w
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
Trustwave
@SpiderLabs Principal Consultant,@MrUn1k0d3r, has announced the release of a new open source tool aimed at aiding Red Team engagements. https://trus.tw/b3a2e#cybersecurity#infosecHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alexander Fischer proslijedio/la je Tweet
We open sourced PathAuditor: a tool for Linux that
@rozek_marta and I worked on this summer. Tl;dr: you can use it to instrument root daemons and find insecure file access patterns like CVE-2019-3461. Check out the code: https://github.com/google/path-auditor … Blog post:https://security.googleblog.com/2019/12/detecting-unsafe-path-access-patterns.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.