Threat Intelligence Report: APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and Domestic Iranian Targets
#apt #cyber_threat_intelligence
#malware_campaing
@ZwLowLevel
DomainTools Investigations | DTI
Threat Intelligence Report: APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and…
Unmasking APT35 (Charming Kitten). New report analyzes leaked internal documents, revealing their operational profile, Exchange attack chains (ProxyShell, EWS), and quota-driven compromise strategies.
#windows_internals #windows_kernel
#import_address_table #reverse_engineering
@ZwLowLevel
https://eversinc33.com/posts/driver-reversing-ii.html
Please open Telegram to view this post
VIEW IN TELEGRAM
#reverse_engineering #reversing
#hardware_hacking
@ZwLowLevel
https://medusalix.github.io/posts/miele-interface/
Please open Telegram to view this post
VIEW IN TELEGRAM
Severin's Blog
Reverse Engineering the Miele Diagnostic Interface
#windows_internals #os_internals
#stack
@ZwLowLevel
https://hulkops.gitbook.io/blog/red-team/x64-return-address-spoofing
Please open Telegram to view this post
VIEW IN TELEGRAM
hulkops.gitbook.io
x64 Return Address Spoofing | HulkOps
#windows_kernel #edr
#windows_internals
@ZwLowLevel
https://github.com/Ap3x/Panoptes
Please open Telegram to view this post
VIEW IN TELEGRAM
GitHub
GitHub - Ap3x/Panoptes: Panoptes Endpoint Detection and Response Solution
Panoptes Endpoint Detection and Response Solution. Contribute to Ap3x/Panoptes development by creating an account on GitHub.
#uefi #hardware_hacking
#firmware_analysis
@ZwLowLevel
https://hackmag.com/security/lenovo-uefi-hack
Please open Telegram to view this post
VIEW IN TELEGRAM
HackMag
Bypassing the Lenovo UEFI Wi‑Fi Whitelist to Upgrade the Wireless Card
Tech magazine for cybersecurity specialists
#windows_internals #windows_telemetry
#os_internals #etw
@ZwLowLevel
https://blog.trailofbits.com/2023/11/22/etw-internals-for-security-research-and-forensics
Please open Telegram to view this post
VIEW IN TELEGRAM
The Trail of Bits Blog
ETW internals for security research and forensics
Why has Event Tracing for Windows (ETW) become so pivotal for endpoint detection and response (EDR) solutions in Windows 10 and 11? The answer lies in the value of the intelligence it provides to security tools through secure ETW channels, which are now also…
BOF to run PE in Cobalt Strike Beacon without console creation
#cobalt_strike #pe
#c2 #offensive_tool
@ZwLowLevel
https://github.com/NtDallas/BOF_RunPe
Please open Telegram to view this post
VIEW IN TELEGRAM
Unusual circuits in the Intel 386's standard cell logic
#hardware_hacking #hardware_analysis
#intel_386 #low_level
@ZwLowLevel
https://www.righto.com/2025/11/unusual-386-standard-cell-circuits.html
Righto
Unusual circuits in the Intel 386's standard cell logic
I've been studying the standard cell circuitry in the Intel 386 processor recently. The 386, introduced in 1985, was Intel's most complex pr...
Forwarded from Golden Byte
#windows_internals #vtl2
#windows_kernel #reversing
@ZwLowLevel
https://howknows.github.io/roooot.github.io/VTL2/Windows_VTL2_Technical_Exploration.html
Please open Telegram to view this post
VIEW IN TELEGRAM
Low Level CO 🇨🇴 pinned «👌 ETW internals for security research and forensics #windows_internals #windows_telemetry #os_internals #etw @ZwLowLevel https://blog.trailofbits.com/2023/11/22/etw-internals-for-security-research-and-forensics»
Please open Telegram to view this post
VIEW IN TELEGRAM
/dev/stack
A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture
1.0 The Silicon Root of Trust: Pre-Boot & Hardware Primitives
The security of the macOS platform on Apple Silicon is not defined by the kernel; it is defined by the physics of the die. Before the first instruction of kernelcache is fetched, a complex, cryptographic…
The security of the macOS platform on Apple Silicon is not defined by the kernel; it is defined by the physics of the die. Before the first instruction of kernelcache is fetched, a complex, cryptographic…
Please open Telegram to view this post
VIEW IN TELEGRAM
Medium
Passcode Writeup (Pwnable.kr)
About Pwnable.kr