Leo Loobeek
570 posts

Leo Loobeek
@leoloobeek
Penetration Tester | Adaptable Adversary | https://t.co/hHYXI8KHIg | Thoughts and tweets are my own
Minnesota, USA Katılım Temmuz 2009
449 Takip Edilen1.4K Takipçiler

After trying LangChain, then Haystack, Rigging has been the best option so far. Removes all the unnecessary abstractions and allows you to focus on building an LLM powered toolset.
dreadnode@dreadnode
Rigging continues to be a core part of our toolkits - new docs here: rigging.dreadnode.io If you want information/tutorials on the roadmap - let us know.
English
Leo Loobeek retweetledi
Leo Loobeek retweetledi

@Vikings @KevOC7 @PhilMackey @DustBaker Season over. 24 hours after the most devastating event of his career, OUR quarterback doesn’t sit home feeling sorry for himself. No, he attends the Kids Club Trick-Or-Treat Trail in Egan. That’s our QB. #Vikings

English
Leo Loobeek retweetledi
Leo Loobeek retweetledi

Before NVIDIA, I was lucky enough to work with @ram_ssk and @drhyrum at Microsoft. We got to write tooling, risk assessments, and attacks IRL. MLSec seems new, but their work on this topic is all over the Security community.
If you’re looking to orient yourself to the current state of ML Security, this is it.
amazon.com/Not-Bug-But-St…
English

@Jean_Maes_1994 @ConsciousHacker Haha I’m no wizard, I’m just as puzzled with COM as the next poor soul to spend time learning it 🫠
English

@coffeegist It's really a social experiment to see who is still hanging out on this platform...
English
Leo Loobeek retweetledi

I wrote a blog post that talks about how we can abuse yet another Chrome Remote Debugging feature to "stalk" end users. posts.specterops.io/stalking-insid…
English
Leo Loobeek retweetledi

In this post, I discuss one key difference in the thinking between sophisticated adversaries and many of the red teams that try to simulate them, as well as what that means for tradecraft and tooling.
jackson_t.gitlab.io/it-depends.html

English
Leo Loobeek retweetledi

I am sharing the slides from my latest presentation: “0-Day Up Your Sleeve – Attacking macOS Environments” I gave at @nullcon
👉securing.pl/en/presentatio…

English
Leo Loobeek retweetledi

An interesting post about Kernel Callback used by EDR. It’s a nice article to read if you want to dive into EDR Kernel Callbacks bypass.
Thanks @synzack21 for the blogpost ! :)
The part about @fdiskyou evil.sys driver and experiments is really nice ! :)
#patching-the-edr-process-notify-callback" target="_blank" rel="nofollow noopener">synzack.github.io/Blinding-EDR-O…
English

@subTee Thanks Casey! Just standing on the shoulders of all your great work 👊
English
Leo Loobeek retweetledi

Packt currently has a few books (including Penetration Testing Azure for Ethical Hackers) on sale on Amazon. Use code “20SECURITY” to get the 20% off discount - packt.link/NEBPw
English
Leo Loobeek retweetledi

New post is up on the @trustedsec blog, this time looking at how to use ProcessDeviceMap to load arbitrary DLL's into a process on start. trustedsec.com/blog/object-ov…
English
Leo Loobeek retweetledi

Introducing Ivy a unique, stealthy method of executing shellcode using VBA and COM objects without dropping office macro documents to disk. Ivy also allows for the unhooking EDRs from the VBA environment. Check it out: github.com/optiv/Ivy 👀 #netsec #redteam #EDR #evasion
English

@HackingLZ The smartest hacker I've ever met @SpecialHoang is an anti cheat wizard
English

Always been a running joke about wanting to improve infosec/malware detection bring over all the anti cheat gaming folks twitter.com/gf_256/status/…
cts🌸@gf_256
English
Leo Loobeek retweetledi

AccChecker is a pretty interesting #lolbin (+ AppLocker Bypass) from the Win SDK. Load a managed DLL with this cmd:
AccCheckConsole.exe -window "Untitled - Notepad" C:\path\to\your\lolbas.dll
More info in this gist: gist.github.com/bohops/2444129…
English
Leo Loobeek retweetledi

github.com/jonaslyk/temp/…
My webdav based reflective loader/per process devicemap based dll injector POC is by now usable.
I would really like to have a OOP wrapper for NT- designing such is surprisingly difficult, but this approach shows potential especially considering simple
English
Leo Loobeek retweetledi

[New Tool] RogueAssemblyHunter 🛡️
Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes
github.com/bohops/RogueAs…
#BlueTeam #ThreatHunting
English




