Mildly irritating things seen by malware nerds:
- Person saying {thing} evades EDR and/or AV, but they've never performed against an enterprise environment with an active Blue Team (they don't know what they're talking about). Yes, your payload avoided basic analysis, but stop…
I created a hypervisor-based emulator for Windows x64 binaries. This project uses Windows Hypervisor Platform to build a virtualized user-mode environment, allowing syscalls and memory accesses to be logged or intercepted. elastic.co/security-labs/…
Project:
github.com/x86matthew/Win…
🦀 𝗥𝘂𝘀𝘁𝗣𝗼𝘁𝗮𝘁𝗼: A Rust implementation of 𝗚𝗼𝗱𝗣𝗼𝘁𝗮𝘁𝗼, abusing 𝗦𝗲𝗜𝗺𝗽𝗲𝗿𝘀𝗼𝗻𝗮𝘁𝗲 to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.
github.com/safedv/RustPot…#redteam#ethicalhacking
🦀 𝗥𝘂𝘀𝘁𝗦𝗼𝗹𝗶𝗹𝗼𝗾𝘂𝘆: Rust-based Internal-Monologue implementation for capturing NetNTLM hashes locally without touching LSASS. Using SSPI for NTLM negotiation and indirect NTAPIs for core operations.
github.com/safedv/RustSol…#redteam#ethicalhacking
Interesting things that happened lately:
October 31st: @safe0x17 released RustVEHSyscalls, a Rust port for LayeredSyscalls — performs indirect syscalls while generating legitimate API call stack frames by abusing VEH
October 30th: @FeribHellscream released a paper on forming a…
🦀 𝗥𝘂𝘀𝘁𝗩𝗘𝗛𝗦𝘆𝘀𝗰𝗮𝗹𝗹𝘀: a Rust port of 𝗟𝗮𝘆𝗲𝗿𝗲𝗱𝗦𝘆𝘀𝗰𝗮𝗹𝗹 that performs indirect syscalls while generating legitimate API call stack frames by abusing VEH, bypassing user-land EDR hooks in Windows.
github.com/safedv/RustVEH…#RedTeam#EthicalHacking
🦀 RustiveDump can now be compiled 𝗮𝘀 𝘀𝗵𝗲𝗹𝗹𝗰𝗼𝗱𝗲 (𝗣𝗜𝗖) using the 𝗥𝘂𝘀𝘁𝗶𝗰𝟲𝟰 𝗱𝗲𝘀𝗶𝗴𝗻. LSASS memory dumper using only 𝗡𝗧 𝗔𝗣𝗜𝘀, supporting 𝗫𝗢𝗥 and 𝗿𝗲𝗺𝗼𝘁𝗲 𝘁𝗿𝗮𝗻𝘀𝗺𝗶𝘀𝘀𝗶𝗼𝗻.
#redteam#ethicalhackinggithub.com/safedv/Rustive…
7K Followers 1K FollowingDocumentation is lies. Source is an abstraction. Assembly is the truth. Also at https://t.co/VYFZ0HHnQn and nostr npub10mx0gx3r2lszrrut8kvr5mt2m8r9ffhn
1K Followers 1K FollowingI love doing hacky stuff | red team operator @CyShieldCompany | adversary simulations newbie | interested in malware & windows security research
1.3M Followers 1K FollowingCo-Founder of Coursera; Stanford CS adjunct faculty. Former head of Baidu AI Group/Google Brain. #ai #machinelearning, #deeplearning #MOOCs
31K Followers 407 FollowingCo-founder, ColdIQ ($6M ARR in under 2 years) | Helping B2B companies scale revenue with the best GTM systems | https://t.co/JbSDyoITFc
10K Followers 115 FollowingInterests in nature, technology, sports, business and economy. Passion for helping individuals to build their brand. DM for paid collaborations.
2K Followers 4 FollowingCo-founder & CEO | VisionBrain | World’s first AI voice assistant helping founders hire in 5 minutes | Helped 34 clients hire faster | Launching soon ↓
7K Followers 1K FollowingDocumentation is lies. Source is an abstraction. Assembly is the truth. Also at https://t.co/VYFZ0HHnQn and nostr npub10mx0gx3r2lszrrut8kvr5mt2m8r9ffhn
90K Followers 161 FollowingCome join us as we go on the adventure of giving visibility into scammers and how they operate. [email protected] (Business ONLY, no investigations)
327 Followers 1K FollowingÉcoute les rumeurs elles savent tout de moi
Barbu au fond d'une cabane, fait du bio ...
Mais où va le monde
https://t.co/0t51Vj7w3w
1K Followers 36 FollowingBinary Golf Grand Prix ; Annual Small File Competition ; Less Is More ; #BGGP5 begins June 21st 2024, ends September 6th 2024;
247K Followers 3K FollowingPentester, Forensic investigator, and former college professor. Trained hackers at every branch of US military and intelligence.
Visit me at https://t.co/G478wufszw
1K Followers 1K FollowingI love doing hacky stuff | red team operator @CyShieldCompany | adversary simulations newbie | interested in malware & windows security research
16K Followers 201 Following@TrustedSec Red Team lead | Hi-Fidelity trolling | Privacy Enthusiast | Putting the "no" in nano | Avatar: https://t.co/3XHmKR8nCk
18K Followers 659 FollowingHacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH
62K Followers 286 FollowingA kiwi coding mimikatz & kekeo
github: https://t.co/eS3LVgU6i0
Head of security services @banquedefrance
Tweets are my own and not the views of my employer
1.4M Followers 1K FollowingBuilding @EurekaLabsAI. Previously Director of AI @ Tesla, founding team @ OpenAI, CS231n/PhD @ Stanford. I like to train large deep neural nets.