Weasel Sec

276 posts

Weasel Sec banner
Weasel Sec

Weasel Sec

@Weasel_Sec

RedTeam | PurpleTeam | PenTest | Chef . Views are mines 🇬🇧🇸🇬

Katılım Nisan 2018
837 Takip Edilen1.2K Takipçiler
Sabitlenmiş Tweet
Weasel Sec
Weasel Sec@Weasel_Sec·
Full access now and no more issue with UAC.
GIF
English
1
3
33
4.4K
Weasel Sec
Weasel Sec@Weasel_Sec·
One way to get around MOTW is to use ClickOnce to download a malicious doc. Since dfsvc.exe handles the download, the file doesn’t get tagged with the MOTW flag.
English
1
11
91
4.4K
Weasel Sec retweetledi
Kyle Cucci
Kyle Cucci@d4rksystem·
I uploaded all the malware samples used in my book #EvasiveMalware to my Github: github.com/d4rksystem/Eva… I received some questions about the lab samples, so just posting it for everyone here 🤓
English
4
79
339
12.7K
Weasel Sec retweetledi
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Why yes, yes we can use ESTSAUTH captured from evilginx to automatically register a passkey
Kuba Gretzky@mrgretzky

@NathanMcNulty This is super cool! (just catching up late after the weekend) Is it possible to generate that passkey using the previously captured cookies or tokens, through phishing? (using browser cookies in general)

English
4
31
130
34.7K
Weasel Sec
Weasel Sec@Weasel_Sec·
@techspence Probably not, since it ultimately invokes wmiprvse.exe.
English
1
0
1
274
spencer
spencer@techspence·
@Weasel_Sec But does it work against crowdstrike?
English
6
1
17
2.5K
Weasel Sec retweetledi
Clandestine
Clandestine@akaclandestine·
GitHub - bats3c/shad0w: A post exploitation framework designed to operate covertly on heavily monitored environments github.com/bats3c/shad0w
English
2
50
242
15.6K
Weasel Sec retweetledi
kmkz
kmkz@kmkz_security·
Goexec is a new take on some of the methods used to gain remote execution on Windows devices. Goexec implements a number of largely unrealized execution methods and provides significant OPSEC improvements overall falconops.com/blog/introduci… Github repo: github.com/FalconOpsLLC/g…
Troisvierges, Luxembourg 🇱🇺 English
3
110
305
15.4K
Kuba Gretzky
Kuba Gretzky@mrgretzky·
You've got to love it when AVs start flagging your official online course phishing training lab website as phishing... 🤦‍♂️ Also figured out Google will block emails including links to the lab. virustotal.com/gui/url/ff9241…
Kuba Gretzky tweet media
English
5
6
43
6.7K
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿@_EthicalChaos_·
This one definitely took way longer than planned, but finished now, just in time for Christmas.
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿 tweet mediaCCob🏴󠁧󠁢󠁷󠁬󠁳󠁿 tweet mediaCCob🏴󠁧󠁢󠁷󠁬󠁳󠁿 tweet mediaCCob🏴󠁧󠁢󠁷󠁬󠁳󠁿 tweet media
English
8
0
55
3.1K
Weasel Sec retweetledi
Rasta Mouse
Rasta Mouse@_RastaMouse·
I FINALLY got call stack spoofing working inside BeaconGate.
Rasta Mouse tweet media
English
7
25
207
16.8K
Weasel Sec
Weasel Sec@Weasel_Sec·
Raw payload. No obfuscation, nothing. Just 9.31MB in size.
Weasel Sec tweet media
English
8
0
17
2.7K
Weasel Sec
Weasel Sec@Weasel_Sec·
@frosty468119564 VirusTotal doesn't allow you to upload files larger than 650MB. I tried uploading a 650MB file and got the same result as with a 250MB file.
English
0
0
4
33
Weasel Sec
Weasel Sec@Weasel_Sec·
Now, same payload increased to 250MB. Just added a lot of null bytes after the raw payload:
Weasel Sec tweet media
English
4
0
6
376
Weasel Sec retweetledi
Kostas
Kostas@Kostastsale·
🚨EDR Telemetry website is live! 🥳 I hope this makes it even easier for folks to compare the telemetry of EDR vendors and visualize their visibility gaps 🙂 ‣ Website🔗edr-telemetry.com ‣ GitHub 🔗github.com/tsale/edr-tele… **Telemetry results reflect the most recent updates from the EDR Telemetry project.
Kostas tweet media
Kostas@Kostastsale

I created the first draft of a website for the EDR telemetry project to help people quickly compare vendor telemetry visibility. What do you think about it? Are there any specific features you want to see for the website? Built with ChatGPT 4o with canvas (wanted to test it out😂) EDR Telemetry project 🔗: github.com/tsale/EDR-Tele…

English
19
281
893
127.2K
Weasel Sec retweetledi
Cube0x0
Cube0x0@cube0x0·
0xC2 is now available and the site has been updated with a brief introduction 0xc2.io/posts/introduc…
English
10
56
231
22.9K