Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Forwarded from Sys-Admin InfoSec
/ Analysis of Amadey Bot Infrastructure Using Shodan

Here you'll see how to use a known c2 to craft additional queries based on html content and certificate information. In total, 12 unique servers will be identified:

https://embee-research.ghost.io/amadey-bot-infrastructure/
Dynamically program the kernel for efficient networking, observability, tracing, and security

this is eBPF… mf… where else to find time for all this..

https://ebpf.io/
Windows LAPS EventIDs and XPath Queries

The Local Administrator Password Solution (LAPS) is a vital tool for managing and securing local administrator accounts in Windows environments. Microsoft recently released an updated version of Windows LAPS, introducing new Event IDs to help administrators monitor and manage their environment effectively. In this blog post, we'll explore these Event IDs and discuss how you can use them to enhance your security and monitoring strategies:

https://www.kaidojarvemets.com/windows-laps-eventids-and-xpath-queries/
How HTTPS Works
Forwarded from Sys-Admin InfoSec
В проекте OpenBLD.net DNS запущен режим OpenBLD+
 
Проект живет благодаря поддержке пользователей, сегодня есть возможность оформить подписку за 3$+, в замен получить:

• Персональную поддержку, помощь в расследовании Cybersecurity инцидентов
• Hardening, AppSec консультации, +консультации по SEO оптимизации Вашего сайта
• Улучшенная скорость доставки Вашего сайта/Домена пользователям OpenBLD.net DNS
• Лого компании или никнейм на сайте проекта со ссылкой на сайт или соц. профиль
• Unlimited доступ для выделенных IP
• Есть вопросы / предложения - welcome @sysadminkz

💪 Или просто закинь по братски на кофе ☕️

*en* - OpenBLD+ Benefits
*ru* - Что дает OpenBLD+
Sys-Admin Up pinned «В проекте OpenBLD.net DNS запущен режим OpenBLD+   Проект живет благодаря поддержке пользователей, сегодня есть возможность оформить подписку за 3$+, в замен получить: • Персональную поддержку, помощь в расследовании Cybersecurity инцидентов • Hardening…»
Freeze[.]rs - payload creation tool used for circumventing EDR

https://github.com/optiv/Freeze.rs
BRUTEPRINT_Expose_Smartphone_Fingerprint_Authentication_to_Brute.pdf
3.4 MB
BRUTEPRINT: Expose Smartphone Fingerprint Authentication to Brute-force Attack

Technical paper
Supply Chain Risk From Gigabyte App Center Backdoor

Recently, the Eclypsium platform began detecting suspected backdoor-like behavior within Gigabyte systems in the wild.

..analysis discovered that firmware in Gigabyte systems is dropping and executing a Windows native executable during the system startup process, and this executable then downloads and executes additional payloads insecurely. It uses the same techniques as other OEM backdoor-like features like Computrace backdoor (a.k.a. LoJack DoubleAgent)..:

https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
Today DigitalOcean supported OpenBLD.net DNS

.. step forward in a joyful mood 🥳
How to attack to DevOps. Defence. Checkilists

1. How to attack to DevOps. 2. How to defence 3. Service configs checklists.
Cyclops Ransomware and Stealer Combo: Exploring a Dual Threat

..new ransomware-as-a-service (RaaS) provider. In addition to offering ransomware services.. which compatible three major platforms: Windows, Linux, and macOS. Technical deep dive research.