Octoberfest7

1.2K posts

Octoberfest7

Octoberfest7

@Octoberfest73

Red Team | Offensive Tool Dev | 2x Course Author @ Zero-Point Security

Katılım Şubat 2022
190 Takip Edilen8.7K Takipçiler
Sabitlenmiş Tweet
Octoberfest7
Octoberfest7@Octoberfest73·
After over a year of work my second course with @_ZeroPointSec is now available! In it students will apply low level windows tradecraft in the writing of Cobalt Strike’s UDRL and Sleepmask components. To celebrate, the BOF course is 25% off thru Jan 12th! zeropointsecurity.co.uk/course/udrl-sl…
English
3
49
188
16.6K
Octoberfest7
Octoberfest7@Octoberfest73·
Seeing decent amounts of discussion along the lines of “you trust your compiler output, trust AI the same” and about how having a “human in the loop” is like SO last year. Either a massive psyop by the Machine Spirit or people have lost their goddamn minds.
English
4
5
37
2.1K
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Anyone interested in what you need for proper loader development in 2026? My talk for @x33fcon was accepted, so I'll take about Malware again. 🔥 It's a unique talk and will only be held there this year! Hope to see some of you in Poland. 😎
S3cur3Th1sSh1t tweet media
English
8
12
118
6K
vx-underground
vx-underground@vxunderground·
@Octoberfest73 @lildylannn I recognized it immediately doing stuff with WinRT. God bless your soul for traversing the darkest corners of their undocumented mess
English
1
0
7
474
Octoberfest7
Octoberfest7@Octoberfest73·
Here is my BOF POC (emphasis on POC...) of this research. As the README states it's not an operationally-ready tool, but it was neat research and I figure the code might be useful for someone else. Thanks to @lildylannn and his colleague for their work! github.com/Octoberfest7/D…
dylan davis@lildylannn

I just dropped some research: DSCourier and would love for your opinion and to check it out!! It’s a novel post-exploitation technique abusing WinGet’s COM API to execute code through Microsoft-signed binaries. GitHub: github.com/DylanDavis1/DS… Blog: dylansec.com/DSCourier/

English
2
26
123
20.8K
vx-underground
vx-underground@vxunderground·
@Octoberfest73 @lildylannn __FIAsyncOperationWithProgress_2_Microsoft__CManagement__CConfiguration__CApplyConfigurationSetResult_Microsoft__CManagement__CConfiguration__CConfigurationSetChangeData *pApplyOp = NULL; Yesssss kingggg. Strip the headers
vx-underground tweet media
English
1
0
48
3.5K
Octoberfest7
Octoberfest7@Octoberfest73·
@0xC0rnbread @lildylannn I haven’t sat down and confirmed myself, but my current understanding is that this is local only, not DCOM
English
0
0
1
105
Octoberfest7
Octoberfest7@Octoberfest73·
@lildylannn Great research! It was quite the adventure working with Claude to get the c-style COM interfaces / headers / etc. still mulling over what the “so what” or use case is really gonna be for the BOF version
English
1
0
2
673
Octoberfest7 retweetledi
dylan davis
dylan davis@lildylannn·
I just dropped some research: DSCourier and would love for your opinion and to check it out!! It’s a novel post-exploitation technique abusing WinGet’s COM API to execute code through Microsoft-signed binaries. GitHub: github.com/DylanDavis1/DS… Blog: dylansec.com/DSCourier/
English
4
103
357
68.7K
Octoberfest7
Octoberfest7@Octoberfest73·
@jamieantisocial They say this, and then 2 minutes later they are using VirtualAlloc, memcpy, and CreateThread to execute their smuggled payload. This is all really just a fancy container to download a payload through, it doesn’t appear to me to offer any advantages from an execution standpoint
English
3
0
25
1.6K
Octoberfest7
Octoberfest7@Octoberfest73·
@cyb3rops @HackingLZ On the offensive side, in my short time, I have seen and felt similar. AI has totally changed the math around releasing “just a POC”. I have angled toward paid course offerings, but there are def things that don’t meet the bar for that I’d like to put out w/o AI snapping up
English
1
0
10
968
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
A bit more context on why I think this way: I’ve shared a lot over the years - thousands of rules, blog posts, methods, tuning ideas, and research. That was always fine as long as turning public ideas into working tools and solid detections still took real time, skill, and engineering effort. What changed is that the cost of copying has dropped a lot, while the pace at which the remaining gap may close is hard to predict. It’s not about being against sharing. It’s about not handing out every detail once the cost of copying it has dropped that much. And to be honest, many of the people acting morally outraged about this are not living by some absolute principle of full openness either. Most people do not share the code, detection logic, methods, or internal know-how that directly supports their livelihood, their employer, or obligations they’ve signed up for. They just usually don’t say that part out loud.
Florian Roth ⚡️@cyb3rops

I’ve deliberately not published blog posts on useful detection ideas and rule-writing methods because I didn’t want LLMs to absorb them. So those ideas stayed private and were shared only with a small group. I doubt I’m the only one making that call. And that probably has consequences for the community over time - not just ours, but any community.

English
9
11
157
16.9K
Octoberfest7
Octoberfest7@Octoberfest73·
@HackingLZ @0xTriboulet @github I have been trying to sponser x64dbg / @mrexodia for a month now, with GitHub always kicking back the payment saying there is a billing problem. Opened a support ticket a month ago and have yet to receive a reply / any update on it
English
0
0
4
652
Justin Elze
Justin Elze@HackingLZ·
I'm going to apologize in advance for daily rants about @github not being a serious company with account suspensions with no notifications, and no direct path to resolve the issue.
English
10
10
95
11.3K
Octoberfest7
Octoberfest7@Octoberfest73·
@LorenzoMeacci @HackingLZ I think you got confused about which thread you were looking at here. This looks like the main thread running the sleepmask code making the WaitForSingleObject call here, not a timer thread. Timer threads absolutely do unwind down to RtlUserThreadStart and BaseThreadInitThunk
Octoberfest7 tweet media
English
1
0
12
1.1K