
@nas_bench @cyb3rops @SecurityAura Code as screenshots sometimes makes sense to avoid your report triggering overzealous AVs. The rest is true. IPs should always half first seen/last seen.
English
Bojack Trojan Horseman
30 posts

@BojackTrojan
I Feel Like My Life Is Just A Series Of Unrelated Wacky Adventures




So, this is the blog written by Crowdstrike, which I addressed a few days back. Fun fact, it was not a threat actor, it was a Red team. I guess crowdstrike's Overwatch team needs to learn how to differentiate between the two 😅. Either way, I reversed the CS kernel driver and found the exact detection it built for BRC4 v1.6.x releases. The v1.7.4 release bypasses these detections.🫡 crowdstrike.com/blog/crowdstri…






















