Pepper$tone

249 posts

Pepper$tone banner
Pepper$tone

Pepper$tone

@Pepperstone_1

King of the Hill

San Jose, CA Katılım Mayıs 2022
6 Takip Edilen602 Takipçiler
Pepper$tone retweetledi
Smukx.E
Smukx.E@5mukx·
Defeating Windows DEP Using ROP Chains Leveraging VirtualAlloc TL;DR: This blog covers Practical exploitation techniques, security mechanisms, methods for bypassing existing protections, based on real world research and certification preparation. Blog:- screetsec.com/blog/defeating…
Smukx.E tweet mediaSmukx.E tweet media
English
1
30
165
5.3K
Pepper$tone retweetledi
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Return Stack Address Overwrite New Medium post. Today we are starting a new series focused on call stack manipulation techniques for Windows offensive security. This first post covers the simplest implementation possible, Return Stack Address Overwrite @s12deff/return-stack-address-overwrite-230a5c9f3ecb" target="_blank" rel="nofollow noopener">medium.com/@s12deff/retur…
English
0
9
41
1.3K
Pepper$tone retweetledi
OccupytheWeb
OccupytheWeb@three_cube·
Compromising Telecom Systems In light of recent investigations into BPFDoor, a backdoor reportedly installed by Chinese actors in telecom systems, we published an article showing how it works and how you can detect it hackers-arise.com/compromising-t…
English
1
9
31
4.2K
Pepper$tone retweetledi
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Hide Loaded Modules in Remote Processes New Medium post. Today we are going to explore a technique to hide loaded modules inside a remote process by manipulating the PEB loader linked lists from outside the target process. With just pure memory writes @s12deff/hide-loaded-modules-in-remote-processes-8d4e5012fc48" target="_blank" rel="nofollow noopener">medium.com/@s12deff/hide-…
English
0
13
88
2.9K
Pepper$tone retweetledi
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
DroidHunter CLI-based Android security assessment framework targeting ethical hackers and professional penetration testers. It integrates multiple attack surfaces into a single tool with a hacker-aesthetic terminal interface. Credit/Source: github.com/hexsecteam/Dro…
7h3h4ckv157 tweet media
English
2
47
267
8.3K
Pepper$tone retweetledi
Vivek | Cybersecurity
Vivek | Cybersecurity@VivekIntel·
Al-Red-Teaming- Guide? The Complete Guide to AI Red Teaming 💥💀 AI Red Teaming Guide is a comprehensive open-source resource for security professionals, researchers, and AI engineers to learn how to identify, test, and mitigate vulnerabilities in modern AI and LLM-based systems. ✨ Key Features: • 🤖 Complete AI Red Teaming methodologies & workflows • 🛡️ Covers NIST AI RMF, MITRE ATLAS & OWASP GenAI • 🎯 Prompt injection, RAG & Agentic AI attack techniques • 🔍 AI security tools, frameworks & real-world case studies • 📋 Incident response, compliance & best practices • 📚 Practical resources for AI security professionals 🔗 github.com/requie/AI-Red-… #AI #CyberSecurity #LLM #RedTeaming #OpenSource #GitHub #AISecurity
Vivek | Cybersecurity tweet mediaVivek | Cybersecurity tweet media
English
4
30
166
6K
Pepper$tone retweetledi
Het Mehta
Het Mehta@hetmehtaa·
Your firewall sees GitHub traffic. It may not see a command channel. Came across OctoC2, a GitHub-native Command & Control framework that uses: - Legit api.github.com for commands & exfil (Issues, Branches, Actions, Gists, etc.) - 11 resilient covert channels with auto-fallback - Strong encryption + GitHub App auth No VPS, no custom domains, no open ports. Just looks like normal dev/CI activity. A useful reminder: allowlisting github.com does not mean the activity behind it is safe. Great research for red teamers, threat hunters, and anyone into cloud-native OPSEC. Tool: github.com/dstours/OctoC2
Het Mehta tweet media
English
3
29
104
7.4K
Pepper$tone retweetledi
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Registry Snapshots for Post Exploitation Enumeration Welcome to this Medium post! I'll introduce rsnap, a tool that snapshots a Windows registry hive from a target machine for offline exploration in a web dashboard format @s12deff/registry-snapshots-for-post-exploitation-enumeration-fbf5798091da" target="_blank" rel="nofollow noopener">medium.com/@s12deff/regis…
English
2
4
21
2.1K
Pepper$tone retweetledi
kozue
kozue@0xkozue·
save it, this is pretty much all you need to get comfortable with vim. everything else comes naturally. MODES i Insert a Append A Append at end of line I Insert at beginning of line o New line below O New line above v Visual V Visual Line Ctrl-v Visual Block Esc Normal mode MOVEMENT h j k l Move w b e Word forward/back/end 0 ^ $ Line start/end gg G File start/end Ctrl-u/d Half page up/down Ctrl-b/f Full page up/down H M L Top/Middle/Bottom of screen % Matching bracket EDIT x Delete character dd Delete line dw Delete word D Delete to end of line yy Copy line yw Copy word p P Paste u Undo Ctrl-r Redo r Replace character . Repeat last change SEARCH /pattern Search forward ?pattern Search backward n N Next/Previous match * # Search word under cursor :noh Clear highlights REPLACE :s/a/b/g Replace on line :%s/a/b/g Replace in file :%s/a/b/gc Replace with confirmation VISUAL v Character V Line Ctrl-v Block > < Indent y Copy d Cut TEXT OBJECTS iw aw Inner/A word ip ap Inner/A paragraph i" a" Inside/Around quotes i( a( Inside/Around () i{ a{ Inside/Around {} WINDOWS :split :vsplit Ctrl-w h/j/k/l Ctrl-w q TABS :tabnew gt gT :tabclose BUFFERS :ls :bnext :bprev :bd FILES :e file :w :wq :q :q! MARKS ma 'a `a REGISTERS :reg "+y "+p MACROS qa q @ a @@ FOLDS za zo zc HELP :help :help
kozue tweet mediakozue tweet media
English
15
27
249
11.3K
Pepper$tone retweetledi
0x12 Dark Development
0x12 Dark Development@Salsa12__·
ETW Session Hijacking New Medium post, today we are looking at the ETW session hijacking technique, redirecting the trace output to Blind Endpoint Monitoring @s12deff/etw-session-hijacking-c8f775cbe085" target="_blank" rel="nofollow noopener">medium.com/@s12deff/etw-s…
English
0
11
52
2.7K
Pepper$tone retweetledi
OccupytheWeb
OccupytheWeb@three_cube·
When the US Invaded Venezuela and captured Maduro, US forces first hit Venezuelan forces with what Trump described as a "discombobulator" 😅 It is actually an LRAD, a Long Range Audio Device. First developed by the US Navy for long range audio communication, it is now being used as a weapon. This might be the ultimate, low-cost home defense device! Learn how easy it is to build in the tutorial below. hackers-arise.com/long-range-aco…
OccupytheWeb tweet media
English
14
150
933
74.5K
Pepper$tone retweetledi
Co11ateral
Co11ateral@co11ateral·
Scanning for Malicious Bluetooth Devices In recent years, as we have investigated home hacking, we have been surprised at how many times the vector of attack is Bluetooth. In our modern homes, bluetooth is used for connectivity between so many devices. With the proliferation of Bluetooth in our daily lives in so many devices, hackers are finding it easy to attack our homes. This tool can help to detect all the Bluetooth devices in your area and their location. In addition, you can determine which have been paired and connected. hackers-arise.com/digital-forens… @three_cube @_aircorridor
Co11ateral tweet media
English
1
23
118
5.2K
Pepper$tone retweetledi
Aircorridor
Aircorridor@_aircorridor·
Satellite Hacking, Part 01: Getting Started Like so many elements of the Internet of Things (IoT), much of their security has relied upon security through obscurity. We intend to change that! hackers-arise.com/satellite-hack… @three_cube
Aircorridor tweet media
English
7
209
1.4K
76K
Pepper$tone retweetledi
Octoberfest7
Octoberfest7@Octoberfest73·
Has anyone played w/ XLL's recently? I'm finding that in up-to-date office double clicking an XLL will open excel but no longer loads/fires the XLL itself. Going into File->Options->Add Ins->Manage I can load the XLL and have it work that way, but not on open anymore
English
2
4
21
13.4K
INFINITE NIGHTMARE
INFINITE NIGHTMARE@MSNightmare2000·
Also had some weird thoughts recently, obviously I'm quite familiar with how GDID function in windows. Hypothetically speaking, you can spoof that GDID if you somehow manage to know some else's GDID and end up incriminating them by uploading stuff that would land anyone in jail.
English
21
32
553
38.5K
Pepper$tone retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
Custom Malware Development (Establishing A Shell Through the Target’s Browser) - Repurposing @beefproject & AutoIt @d.bougioukas/red-team-diary-entry-3-custom-malware-development-establish-a-shell-through-the-browser-bed97c6398a5" target="_blank" rel="nofollow noopener">medium.com/@d.bougioukas/…
English
0
34
87
0