Red Blue Team – Telegram
Red Blue Team
5.02K subscribers
38 photos
5 videos
33 files
1.43K links
-> 20 June 2019

]-> RedTeam | BlueTeam | Pentest

[-> Blue Team @BlueTeamKit
Download Telegram
Scheduled Task Tampering

In this post we will explore two approaches that can be used to achieve the same result: create or modify a scheduled task and execute it, without generating the relevant telemetry. First, we will explore how direct registry manipulation could be used to create or modify tasks and how this did not generate the usual entries in the eventlog. Finally, an alternative route based on tampering with the Task Scheduler ETW will be presented that will completely suppress most of logging related to the Task Scheduler.

https://labs.f-secure.com/blog/scheduled-task-tampering/

@BlueRedTeam
#CVE-2022

CVE-2022-26809 is a vulnerability in Remote Procedure Call Runtime

https://github.com/ExploitPwner/CVE-2022-26809-RCE-POC

@BlueRedTeam
#Blue_Team

Detecting Hypervisor-assisted Hooking

https://momo5502.com/blog/?p=255

@BlueRedTeam