RistBS

41 posts

RistBS banner
RistBS

RistBS

@RistBs

🇫🇷 maldev enjoyer & windows internals explorer | 🏆 Offshore & APTlabs

Katılım Ekim 2021
177 Takip Edilen279 Takipçiler
Yarden Shafir
Yarden Shafir@yarden_shafir·
I get lots of requests for recommended resources for learning Windows, exploitation, VR, etc. I have some good links but there’s lots of others I don’t know or forgot about. Give me your best suggestions please! Feel free to link your own stuff, I wanna see it!
English
23
121
408
65.2K
RistBS
RistBS@RistBs·
@aahmad097 very nice project, I brought a PoC based on the same concept a while ago but with only ContextMenuHandlers shell extension
English
0
0
0
80
RistBS retweetledi
Zohdy
Zohdy@7odaZohdy·
My latest blog I worked on “Hunting for A New Stealthy Universal Rootkit Loader”, We discovered a threat actor we believe is the same actor behind FiveSys is actively abusing WHQL portal for signing 75 kernel drivers in 2022/2023. trendmicro.com/en_us/research…
English
1
1
4
530
RistBS
RistBS@RistBs·
@Jhaddix Thank you for that, I appreciated it 😼
English
0
0
0
171
ghostface
ghostface@Imghostfaceee·
@0gtweet I can't start the service, even with admin priv
English
2
0
1
190
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Kinda (too?) complex persistency: WDI. The DLL specified in Control\WDI\DiagnosticModules is loaded in the LocalSystem context by the WDISystemHost when the proper message arrives to ALPC specified by Control\WDI\Config\ServerName. Such ALPC can be sent by an unprivileged user.
English
2
3
26
5.2K
RistBS
RistBS@RistBs·
@NUL0x4C @modexpblog the only implementation of the structure I have seen so far is #L63" target="_blank" rel="nofollow noopener">github.com/JKornev/NTlib/…
English
1
0
1
61
NULL
NULL@NUL0x4C·
@RistBs @modexpblog yupp, my goal is to use it for that purpose, but its not clear how
English
1
0
0
97
NULL
NULL@NUL0x4C·
does anyone know anything about the "ProcessSystemCallFilterPolicy" flag /utilizing it for a mitigation policy
English
3
0
4
1.9K
RistBS
RistBS@RistBs·
@_nwodtuhs @Alh4zr3d So, better calls the ticket that comes after TGS_REP a Service Ticket (ST) instead of TGS
English
1
0
4
212
Chetan Nayak (Brute Ratel C4 Author)
Here it goes. A detailed blog on proxying your DLL loads and hiding the original callstack from userland hooks/ETW with a new set of undocumented API and some hacky tricks. Code is on my Github repository. This one was a brain buster 🔥 0xdarkvortex.dev/proxying-dll-l…
English
9
108
315
42.3K