Source Byte – Telegram
Source Byte
7.76K subscribers
847 photos
73 videos
678 files
1.68K links
هشیار کسی باید کز عشق بپرهیزد
وین طبع که من دارم با عقل نیامیزد
Saadi Shirazi 187
Download Telegram
Understanding x86_64 Paging

Link

#internals
#windows
------
@islemolecule_source
Microsoft has observed a subset of Iran-based threat actor Mint Sandstorm (PHOSPHORUS) employing new TTPs to improve initial access, defense evasion, and persistence in campaigns targeting individuals at universities and research orgs.


https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/

#TTP , #red_team
———
@islemolecule_source
Elevate process privileges to the System or Trustedinstaller

Link

#malware_dev
#windows
-------
@islemolecule_source
MikroTik router reverse engineering (SOHO, embedded/IoT devices)
Excellent writeup by @hgarrereyn and @__comedian


https://margin.re/2022/06/pulling-mikrotik-into-the-limelight/

Slides (RECon)

#iot ,
———
@islemolecule_source
MutationGate is a new approach to bypass EDR's inline hooking by utilizing hardware breakpoint to redirect the syscall.

https://github.com/senzee1984/MutationGate

#malware_dev
#edr
----
@islemolecule_source
Ghidra Binary Diffing Engine

credit: @clearseclabs


clearbluejar.github.io/posts…


———
@islemolecule_source
👍2
Forwarded from UnknownHat
BlackCat(ALPHV).zip
1.6 MB
BlackCat Ransomware (ALPHV) Configuration Tool, You Just Need To Understand How This Tool Works

Note - Use RDP For Testing

Source : https://www.varonis.com/blog/blackcat-ransomware
👍2
Forwarded from UnknownHat
Fuzzer Development: The Soul of a New Machine
credit : @h0mbre_


https://h0mbre.github.io/New_Fuzzer_Project/#

#fuzzer
———
@islemolecule_source
👍1
WADComs is an interactive cheat sheet ->Windows/AD

https://wadcoms.github.io

#windows #AD
----------
@islemolecule_source
👍1
Payload creation framework to around EDR bypass.

Link

#edr
--------
@islemolecule_source
👍1
Win32 programming
Link

#win_api
------------
@islemolecule_source
👍1
Forwarded from VX-SH
cobaltstrike-dist.tgz
4.2 MB
Distribution Packages (Jan 12, 2024)
👍1
Anti debugging techniques
Link

#reverse
#win_api
------------
@islemolecule_source
👍1
Windows programming tutorial
Link

#win_api
-----------
@islemolecule_source
👍1
Mastering C++ Programming: Modern C++ 17 at your fingertips
Link

#win_api
-----------
@islemolecule_source
👍2
Jeffrey_Richter,_Christophe_Nasarre_Windows_via_C_C++_Microsoft.pdf
7.1 MB
Windows via c / c++

#win_api
------------
@islemolecule_source
👍2
Windows System Programming Fundamentals.7z
447.8 MB
Windows System Programming Fundamentals
>Course Overview
>Windows Foundations
>Application Development Basics
>Objects and Handles

#win_api
-----------
@islemolecule_source
👍2