Two Seven One Three

244 posts

Two Seven One Three banner
Two Seven One Three

Two Seven One Three

@TwoSevenOneT

Chief Security Officer (CSO) || Security Researcher at https://t.co/YsorB5YEAu || Penetration Tester || Red Teamer || Social Engineering Awareness Trainer

Katılım Eylül 2024
2.1K Takip Edilen4.7K Takipçiler
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
Some powerful built-in Windows 11 programs are allowed to write files to Defender’s working directory: \System32\msiexec.exe \Register-CimProvider.exe \svchost.exe \lsass.exe Tools and methods to find these whitelisted programs for other #antimalware Github: /TwoSevenOneT/DefenderWrite
Two Seven One Three tweet media
English
0
30
147
9.6K
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
Challenge: Drop #mimikatz onto a drive with the latest Windows 11. 1. Found a way to write a file into Windows Defender’s working directory: Success ✅ 2. Dropped "mimikatz.exe" into that folder: Failed 🛑 Conclusion: Windows Defender does not exclude its own executable folder
Two Seven One Three tweet media
English
0
11
52
7.9K
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
@DXevj7ck The purpose is to prevent EDRs from connecting to their servers, with low user privs
English
1
0
0
211
Maekawa
Maekawa@DXevj7ck·
@TwoSevenOneT Why don’t you try blocking the URL in Windows Defender?
English
1
0
0
320
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
While I was trying to evade cloud-based EDRs, I accidentally found a way to temporarily block a client's machine network with a POC running as a Normal user. Not using the Windows Filtering Platform (WFP) which requires Admin priv I haven't thought of exploitation scenarios for this tool yet, it might be a dead-end #antimalware research direction 🤔 #redteam
Two Seven One Three tweet media
English
3
31
162
15.7K
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
@huntnp007 Yep, Mimi when you want to check whether an exec malicious behavior triggers an alert or not. It's just a quick check.
English
0
0
0
77
HolyM
HolyM@HolyMoly84103·
@TwoSevenOneT 🤣 one of the best solution for every one who need to test av is work...
English
1
0
0
175
Thomas Hinson
Thomas Hinson@HonkyTonkHer0·
@TwoSevenOneT Not all modern EDR tools will alert when mimikatz or a similar tools write to disk. They will only alert once the tool is utilized. This varies by customer configuration as well.
English
1
0
0
293
Two Seven One Three retweetledi
Mr.Z
Mr.Z@zux0x3a·
I am releasing a new toolkit I built for IIS-based lateral movement and code execution within IIS worker pool process's memory. Phantom ASPX Loader & PhantomLink -- a two-part toolkit for reflectively loading native DLLs into IIS w3wp.exe worker processes via ASPX. github.com/zux0x3a/Phanto…
GIF
English
4
78
250
16.7K
Two Seven One Three retweetledi
Tim Blazytko
Tim Blazytko@mr_phrazer·
Recently my RE workflow moved into sandboxed VMs where agents have full control over the environment. I needed an MCP server that runs headless in the same sandbox and exposes way more of the #BinaryNinja API than others. Here's the release: github.com/mrphrazer/bina…
English
3
50
273
36.9K
Two Seven One Three retweetledi
Clandestine
Clandestine@akaclandestine·
GitHub - 0xsh3llf1r3/ColdWer: Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass github.com/0xsh3llf1r3/Co…
English
0
34
128
9.5K
Two Seven One Three
Two Seven One Three@TwoSevenOneT·
@7uckzero Yes, what's important is how we make a valid service "crash". If we use a custom payload to trigger it, then the failure recovery function isn't very useful anymore.
English
0
0
0
66