Patryk Czeczko

18 posts

Patryk Czeczko

Patryk Czeczko

@0xPat

Red/purple teamer https://t.co/AhR2vq4vuU

Warsaw, Poland Katılım Şubat 2020
27 Takip Edilen1.3K Takipçiler
Patryk Czeczko retweetledi
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Eliminate huge part of lateral movement scenarios with one command: "reg.exe add HKLM\SYSTEM\CurrentControlSet\Control /v DisableRemoteScmEndpoints /t REG_DWORD /d 1" It will make Service Control Manager deaf to remote management. Everything else works properly.
Grzegorz Tworek tweet media
English
10
300
976
0
Patryk Czeczko
Patryk Czeczko@0xPat·
@zz0eyu I think the memory pages are not shared by default, unless there's some interaction going on from other process, like debugger for example.
English
0
0
0
0
zoemurmure
zoemurmure@zz0eyu·
@0xPat I think there's a bug in your third article.
zoemurmure tweet media
English
1
0
0
0
Patryk Czeczko retweetledi
Vlado Vajdic
Vlado Vajdic@vvlado·
Detecting APT29: MITRE EDR evaluations round 2 - Jorrit Folmer - Medium -> not everyone is a winner! @jorritfolmer/detecting-apt29-mitre-edr-evaluations-round-2-a8dcf7a3f486" target="_blank" rel="nofollow noopener">medium.com/@jorritfolmer/…
English
0
4
2
0
Patryk Czeczko retweetledi
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Wanted to demonstrate AdjustTokenPrivileges() -> SomePrivilegedCall() sequence, and failed with SetSystemTime(). And now I know: SetSystemTime() tries to adjusts privileges on it's own, not even checking the result, and then calls NtSetSystemTime() syscall. Interesting...
Grzegorz Tworek tweet media
English
0
6
20
0