Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @repdet
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @repdet
-
Gleb Gritsai proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Gleb Gritsai proslijedio/la je Tweet
KDU, Kernel Driver Utility - driver loader (and not only) bypassing Windows x64 Driver Signature Enforcement with support of various "functionality" providers - including Unwinder's RTCore, https://github.com/hfiref0x/KDU pic.twitter.com/s154qYlIKR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Can your EDR detect symbolic link callback rootkits? Because ours sure as heck can't.
@aionescu and I wrote about these! https://windows-internals.com/dkom-now-with-symbolic-links/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
#FakeLogonScreen is a C# utility to steal a user's password using a fake Windows logon screen. This password will then be validated and saved to disk. Useful in combination with#CobaltStrike's execute-assembly command. https://github.com/bitsadmin/fakelogonscreen …pic.twitter.com/2pAOk9InLMHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
@irsdl’s first post is a writeup for an RCE in SharePoint https://www.mdsec.co.uk/2020/01/code-injection-in-workflows-leading-to-sharepoint-rce-cve-2020-0646/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
New blog (and tool): Attacking Azure, Azure AD, and Introducing PowerZurehttps://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
If
@tiraniddo's DotnetToJScript is blocked on newer versions of Windows or if it gets flagged by AMSI, you can use Excel automation via a COM object as an alternative to execute shellcode from JScript or VBScript w/o touching disk. PoC for x86 & x64 here:https://github.com/outflanknl/Scripts/blob/master/ShellcodeToJScript.js …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Sharing a new demo + an article on BlueKeep dissection (CVE-2019-0708) using REVEN. See how data Tainting, Memory History, and its Python API streamline the RE process to quickly and accurately analyze the root-cause and behavior at the system level. https://blog.tetrane.com/2020/01/22/bluekeep.html …pic.twitter.com/aA8gvu2Brs
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Invoke-WMILM. PoC script for various methods to achieve authenticated remote code execution via WMI, without (at least directly) using the Win32_Process classhttps://github.com/Cybereason/Invoke-WMILM …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
#lsassy v2 is out
Dump credentials on multiple hosts
New dumping method using #dumpert (@OutflankNL) thanks to@Blurbdust
Can be used as a #library in other python project
Fully documented wiki !
Needs some testing, open issues if need be
https://github.com/Hackndo/lsassy Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
TIL you can implement a web server using awk https://rosettacode.org/wiki/Hello_world/Web_server#AWK …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Scared by latest CVE-2020-0601 certificate spoofing vulnerability? We did a
#suricata detection rule for you. It covers all known exploitations of TLS certificates and executable signing. Find it here: https://github.com/ptresearch/AttackDetection/blob/master/CVE-2020-0601/cve-2020-0601.rules …#ChainOfFools#CurveBallHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
RDP to RCE: When Fragmentation Goes Wronghttps://www.kryptoslogic.com/blog/2020/01/rdp-to-rce-when-fragmentation-goes-wrong/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Lmao. I just hope you don't work in the server room or data centre ;)pic.twitter.com/LoXbz75aWS
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
I spent some time learning about blockdlls and parent process spoofing from
@_RastaMouse and@_xpn_ . Using a recent sample from SubTee, I modified it to spoof the parent process and inject x64 shellcode from a dll on UNC into hidden iexplore.exe. https://gist.github.com/rvrsh3ll/54088dcd81a09e99421a8c5692124705 …pic.twitter.com/V93FAn6iIFHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Today in my latest post, I share my top 10 recommendations for free resources to check out if you're getting started in
#threatintel. I mixed it up with well-known classics as well as some lesser-known and newer sources - it was tough to choose just a few!https://medium.com/katies-five-cents/a-top-10-reading-list-if-youre-getting-started-in-cyber-threat-intelligence-c11a18fc9798 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
ticket to ride, new attacks on desfire ev1https://www.youtube.com/watch?v=ZSrOq40z1i8 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
We’re excited to announce the initial release of ATT&CK for ICS! You can find the ICS knowledge base at https://attack.mitre.org/ics and a blog post by
@ojalexander explaining what’s new and different here: https://medium.com/mitre-attack/launching-attack-for-ics-2be4d2fb9b8 …. Thank you to everyone who helped us get here!pic.twitter.com/xouwwdufV1Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je Tweet
Just published some thoughts on red teaming, how to approach it, procure it and get in to it...https://link.medium.com/eV1myC6NM2
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Gleb Gritsai proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.