Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @med0x2e
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @med0x2e
-
Prikvačeni tweet
A signature based bypass for AMSI using GadgetToJScript; a tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS based scripts.
#redteamhttps://github.com/med0x2e/GadgetToJScript …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Want to see how the
@Mandiant red team weaponizes@FireEye threat intel for R&D and TTP development? Check out some research I did with@evan_pena2003 and@FuzzySec. Also includes some new executables that can be used for DLL abuse.https://www.fireeye.com/blog/threat-research/2020/01/abusing-dll-misconfigurations.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Wrote a post on how to use GadgetToJScript with Covenant & Donut https://3xpl01tc0d3r.blogspot.com/2020/02/gadgettojscript-covenant-donut.html …
#Covenant#Donut#GadgetToJScript#redteam#processinjection Thanks to@med0x2e for the answering my queries and helping me while exploring#GadgetToJScript tool
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
That epic Microsoft moment

#cve20200601#curveball Recently worked on#mimikatz and ECC, so yes, 10 and 2016/2019 only. Previous versions like Windows 7 did not support personnal EC curves (only few NIST standard ones)pic.twitter.com/EayEuFVv1JPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Mohamed El Azaar proslijedio/la je Tweet
"Information is power. But like all power, there are those who want to keep it for themselves." Aaron Schwartz would be 33 by now.pic.twitter.com/gpOGNJa8kI
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
New blog post looking at how Cobalt Strike’s “blockdlls” command works, how to recreate it in our own payloads, and a quick look at Arbitrary Code Guard.https://blog.xpnsec.com/protecting-your-malware/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Quick POC to spawn a process with PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON using VBA. https://gist.github.com/xpn/f44faa0c548d89f9957fa3316380a42f …pic.twitter.com/qInZYFagcG
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you've ever come across an IOS application built with Kony & Frida fu doesn't help in bypassing SSL pinning; add below entries to info.plist: <key>allowselfsignedcertificate</key> <true/> <key>allowbundledonly</key> <string>NO</string> package -> sign -> deploy -> have fun.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Our new
@OutflankNL blog post on abusing the SYLK file format. This 1980s file type can host macros in modern versions of MS Office / Excel without hitting protected mode. Post includes recommendations for mitigation (note: active abuse in the wild).https://outflank.nl/blog/2019/10/30/abusing-the-sylk-file-format/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
To be specific, 10 lines of code to inject shellcode into the current running process using a classic CreateThread based shellcode injection method.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Calling win32 API from jscript/vbscript using ExecuteExcel4Macro in less than 10 lines of JS code. 0/56 on VT and not getting flagged by WinDefender/AMSI for the moment. A simple script to automate the process; & credits:
@OutflankNLhttps://github.com/med0x2e/genxlmPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
My first blog on abusing the Service Control Manager and DLL hijacks for lateral movement. I cover methodology, detections and proof of concept code. Thanks to
@mattifestation/@Cyb3rWard0g for all their detection contributions!https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Added VBA support (-e for hex or b64 VBA gadgets encoding)https://github.com/med0x2e/GadgetToJScript/tree/master/GadgetToJScript …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON can be your friend
#isthishowyoudoredteamtipsHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Running Mimikatz using GadgetToJScript from JS or VBS ‘cscript mimi.js privilege::debug < safe.txt’ Steps:https://gist.github.com/med0x2e/cc10d42b1f581507013e801da2651c74 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Releasing my bloodhound helper tool, cypheroth. It helps save time you would have spent running bloodhound cypher queries in the neo4j web interface by dumping all the important info out to spreadsheets. Comes with a great set of starting queries. https://github.com/seajaysec/cypheroth …pic.twitter.com/bIfN8YLxqz
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Don't like AV on the box? Hook the admin password prompt with Frida and disable it as regular user
https://twitter.com/FSDominguez/status/1182590814775660544 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
Combine (
@byt3bl33d3r)'s SILENTTRINITY with (@med0x2e)'s GadgetToJScript. We can use js/vbs as a stager for SILENTTRINITY.https://github.com/3gstudent/GadgetToJScript …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mohamed El Azaar proslijedio/la je Tweet
I don't remember who posted this on Twitter a few years ago, but whoever you are: you have improved every night I've spent in a hotel since.pic.twitter.com/NpuuumqHV8
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.