Archive

Archive

1481 bookmarks
Custom sorting
The Triforce of Initial Access
The Triforce of Initial Access
Unlock the power of Microsoft Office with the ultimate Red Teaming toolkit, leveraging Evilginx, ROADtools, TeamFiltration, and Bobber to gain…
·trustedsec.com·
The Triforce of Initial Access
More on Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
More on Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
Imagine that you’re a SOC (Security Operations Center) analyst receiving an alert about suspicious behavior from a binary on an EC2 instance. After checking the binary on VirusTotal, you find it was an AWS-developed software signed by Amazon. Further investigation reveals that it communicated only with Amazon-owned IP addresses.
·mitiga.io·
More on Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
Breaking Out of Citrix and other Restricted Desktop Environments | Pen Test Partners
Breaking Out of Citrix and other Restricted Desktop Environments | Pen Test Partners
Introduction Many organisations are turning to virtualisation of apps and desktops. This often involves virtualisation platforms such as Citrix to deliver these services.  Get your configuration or lock-down wrong and you’ll find users ‘breaking out’ of the environment you thought you had secured. It might not be long after that when you find that your entire domain […]
·pentestpartners.com·
Breaking Out of Citrix and other Restricted Desktop Environments | Pen Test Partners
Decrypting and Abusing Predefined BIOCs in Palo Alto Cortex XDR
Decrypting and Abusing Predefined BIOCs in Palo Alto Cortex XDR
Research shows how Palo Alto Cortex XDR predefined BIOC behavioral rules can be decrypted and analyzed. By understanding rule logic and built-in exceptions, attackers can adapt techniques to evade detection and bypass behavioral protections.
·core-jmp.org·
Decrypting and Abusing Predefined BIOCs in Palo Alto Cortex XDR
Silent Harvest: Extracting Windows Secrets Under the Radar
Silent Harvest: Extracting Windows Secrets Under the Radar
“Silent Harvest” explains how attackers can quietly extract sensitive Windows secrets such as credentials and security keys by abusing legitimate registry and system mechanisms, avoiding LSASS dumping and bypassing many common EDR detections.
·core-jmp.org·
Silent Harvest: Extracting Windows Secrets Under the Radar
Patch diff to SYSTEM — Elastic Security Labs
Patch diff to SYSTEM — Elastic Security Labs
Leveraging LLMs and patch diffing, this research details a Use-After-Free vulnerability in Windows DWM, demonstrating a reliable exploit that achieves escalation from low-privileged user permissions to SYSTEM.
·elastic.co·
Patch diff to SYSTEM — Elastic Security Labs
Yet Another ZIP Trick Writeup
Yet Another ZIP Trick Writeup
A detailed walkthrough of the 'Yet Another ZIP Trick' challenge from HackArcana, covering schizophrenic ZIP file creation and binary exploitation techniques.
·husseinmuhaisen.com·
Yet Another ZIP Trick Writeup
Атаки на финансовый сектор глазами PT SWARM: социальная инженерия 2025
Атаки на финансовый сектор глазами PT SWARM: социальная инженерия 2025
Мы в PT SWARM, как сейчас модно говорить, любим челленджи — ставить перед собой большие и сложные задачи, которые решаем путем их разбивки на
·ptresearch.media·
Атаки на финансовый сектор глазами PT SWARM: социальная инженерия 2025
Persistence: The Art of Staying In
Persistence: The Art of Staying In
The definitive red team guide to persistence across every platform: 50+ techniques across Windows (Registry, IFEO, SSP, Time Provider, Office T1137, Accessibility Features, Application Shimming), Scheduled Tasks, WMI, Services, DLL/COM/AppDomainManager, UEFI Bootkits, Active Directory (Golden/Diamond/Sapphire Ticket, AdminSDHolder, DCSync, DCShadow, Skeleton Key, DSRM, GPO), Linux (cron, systemd, SSH, PAM, eBPF rootkits, LKM, WSL), macOS (LaunchAgents, Login Items, Dylib Hijacking), and Cloud (Azure/AWS/GCP, Kubernetes). Real APT TTPs from Volt Typhoon, Salt Typhoon, Turla, Lazarus, APT29, APT28, APT41, UNC3944/Scattered Spider. Full OPSEC tradecraft.
·0xdbgman.github.io·
Persistence: The Art of Staying In
Living off the Process
Living off the Process
Hello again everyone! Hope the start to the new year is treating you well. I am excited to share a new blog post with you! Furthermore, I’d consider the content shared in today’s post to be the most time I’ve spent in researching a particular offensive security topic/technique 😹 I’d say I spent well over a month looking into this exciting topic and I wanted to make sure I had all my research completed before I jumped in to making a post. Without further ado, I give you my take on what I’d like to call: Living off the Process! This is a technique that does as the name implies: We use what is already available to us in the remote process of our choosing to accomplish a given goal. In this case, the goal will be to write shellcode indirectly into the remote process with as low of a footprint as possible. When I say indirectly, I mean we won’t be using WriteProcessMemory to write the shellcode. That API does play a small role, but ultimately we will be indirectly writing our shellcode in 8 byte chunks using ROP gadgets and assembly stubs all made available in the remote process. We will also avoid the creation of RWX regions of memory. Here’s a quick overview on how it all works. We will be looking for:
·g3tsyst3m.com·
Living off the Process