w0rk3r's Windows Hacking Library – Telegram
w0rk3r's Windows Hacking Library
1.55K subscribers
10 photos
577 links
Manual job, I'm not a bot ;)

@BlueTeamLibrary
@W0rk3r
Download Telegram
Invoke-Phant0m

This noscript walks thread stacks of Event Log Service process (spesific svchost.exe) and identify Event Log Threads to kill Event Log Service Threads. So the system will not be able to collect logs and at the same time the Event Log Service will appear to be running.

https://artofpwn.com/phant0m-killing-windows-event-log.html
https://github.com/hlldz/Invoke-Phant0m

@WindowsHackingLibrary
Invoke-WMILM

This is a PoC noscript for various methods to acheive authenticated remote code execution via WMI, without (at least directly) using the Win32_Process class. The type of technique is determined by the "Type" parameter.

https://github.com/Cybereason/Invoke-WMILM/blob/master/README.md

@WindowsHackingLibrary