Nicolas Bareil
283 posts







I’ve recently done a deep dive into how IIS view state machine keys are generated and how they are used to decrypt view state messages. I’ve written up my findings in a new blog post and developed an application to assist with the decryption of view states zeroed.tech/blog/decryptin…

If you can read the detection rules, evading them becomes a lot easier. New write-up on decrypting Cortex XDR behavioral rules and abusing Global Whitelists by @p0w1_. TL;DR: just put ':\Windows\ccmcache' in your command line. Fixed in Agent 9.1. labs.infoguard.ch/posts/decrypti…


I wrote a new blog: Hunting reflected .NET assemblies at scale with Velociraptor, detecting CLR patching, and dumping in-memory payloads for triage. #DFIR #Velociraptor labs.infoguard.ch/posts/clraptor…











Online #powershell deobfuscator base on #tree-sitter minusone.skyblue.team



