Snakes on a Domain: An Analysis of a Python Malware Loader
https://www.huntress.com/blog/snakes-on-a-domain-an-analysis-of-a-python-malware-loader
https://www.huntress.com/blog/snakes-on-a-domain-an-analysis-of-a-python-malware-loader
Huntress
Snakes on a Domain: An Analysis of a Python Malware Loader | Huntress
Join us on a threat analysis journey as we discover a very shady Python—and a very friendly RAT.
Pwning ManageEngine — From Endpoint to Exploit | by Erik Wynter | Oct, 2022 | Medium
https://medium.com/@erik.wynter/pwning-manageengine-from-endpoint-to-exploit-bc5793836fd
https://medium.com/@erik.wynter/pwning-manageengine-from-endpoint-to-exploit-bc5793836fd
Medium
Pwning ManageEngine — From Endpoint to Exploit
A deep dive into CVE-2021–42847
GitHub - cisagov/RedEye: RedEye is a visual analytic tool supporting Red & Blue Team operations
https://github.com/cisagov/RedEye/
https://github.com/cisagov/RedEye/
GitHub
GitHub - cisagov/RedEye: RedEye is a visual analytic tool supporting Red & Blue Team operations
RedEye is a visual analytic tool supporting Red & Blue Team operations - cisagov/RedEye
Practical Attacks against NTLMv1 - TrustedSec
https://www.trustedsec.com/blog/practical-attacks-against-ntlmv1/
https://www.trustedsec.com/blog/practical-attacks-against-ntlmv1/
TrustedSec
Practical Attacks against NTLMv1
Two different attack methods will be covered: Authentication Downgrade -> Cracking LDAP Relay -> Resource Based Constrained Delegation (RBCD) / Shadow…
Hardware Trojans Under a Microscope | by Ryan Cornateanu | Oct, 2022 | Medium
https://ryancor.medium.com/hardware-trojans-under-a-microscope-bf542acbcc29
https://ryancor.medium.com/hardware-trojans-under-a-microscope-bf542acbcc29
Medium
Hardware Trojans Under a Microscope
Table of Contents
GitHub - VirtualAlllocEx/Payload-Download-Cradles: This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.
https://github.com/VirtualAlllocEx/Payload-Download-Cradles
https://github.com/VirtualAlllocEx/Payload-Download-Cradles
GitHub
GitHub - VirtualAlllocEx/Payload-Download-Cradles: This are different types of download cradles which should be an inspiration…
This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections. - VirtualAlllocEx/...
GitHub - projectdiscovery/katana: A next-generation crawling and spidering framework.
https://github.com/projectdiscovery/katana
https://github.com/projectdiscovery/katana
GitHub
GitHub - projectdiscovery/katana: A next-generation crawling and spidering framework.
A next-generation crawling and spidering framework. - projectdiscovery/katana
Fantastic Rootkits: And Where to Find Them (Part 1)
https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-1
https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-1
Cyberark
Fantastic Rootkits: And Where to Find Them (Part 1)
Introduction In this blog series, we will cover the topic of rootkits — how they are built and the basics of kernel driver analysis — specifically on the Windows platform. In this first part, we...
GitHub - ryanries/PassFiltEx: PassFiltEx. An Active Directory Password Filter.
https://github.com/ryanries/PassFiltEx
https://github.com/ryanries/PassFiltEx
GitHub
GitHub - ryanries/PassFiltEx: PassFiltEx. An Active Directory Password Filter.
PassFiltEx. An Active Directory Password Filter. Contribute to ryanries/PassFiltEx development by creating an account on GitHub.
GitHub - wavvs/nanorobeus: COFF file (BOF) for managing Kerberos tickets.
https://github.com/wavvs/nanorobeus
https://github.com/wavvs/nanorobeus
GitHub
GitHub - wavvs/nanorobeus: COFF file (BOF) for managing Kerberos tickets.
COFF file (BOF) for managing Kerberos tickets. Contribute to wavvs/nanorobeus development by creating an account on GitHub.
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!
Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/
Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/