Marcelo

222 posts

Marcelo banner
Marcelo

Marcelo

@spamv

(In)Security Ninja Turtle | Red Team stuff

Zurich, Switzerland Katılım Haziran 2010
514 Takip Edilen168 Takipçiler
Marcelo retweetledi
Maddie Stone
Maddie Stone@maddiestone·
We're naming names 🔥 because the harm is not hypothetical. Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates. blog.google/threat-analysi…
Maddie Stone tweet media
English
13
276
608
135K
Marcelo
Marcelo@spamv·
Anyone hanging around too? :D
English
0
3
13
1K
SkelSec
SkelSec@SkelSec·
Look what came in the mail today
SkelSec tweet media
English
18
3
97
12.1K
Marcelo
Marcelo@spamv·
@SkelSec That’s probably your best tweet..🤣🤣
English
0
0
0
47
Marcelo
Marcelo@spamv·
@_xpn_ Ban yourself from those TTPs (until you really run out of time.. :D)
English
0
0
1
0
Adam Chester 🏴‍☠️
Do any Red Teams have any techniques/tips for avoiding always using the same old TTPs? Each assessment I try and use something new (where possible) but interested in any tips that others have that work.
English
18
12
117
0
Marcelo retweetledi
Omri Segev Moyal
Omri Segev Moyal@GelosSnake·
I thought the Messiah would come faster than this. Microsoft to disable macro by default in Excel 4.0
Omri Segev Moyal tweet media
English
7
117
344
0
Jarno
Jarno@jmoosdijk·
Ever not 100% sure if a Cobalt Strike command uses Fork&Run or executes code within a Beacon process (i.e. BOF)? This simple aggressor script helps you by colouring commands based on their type: github.com/outflanknl/Hel…
English
8
117
270
0
Marcelo
Marcelo@spamv·
@commial Yes, the first 5 bytes of headers are also clear for me, the other ones still not so much. I'll try to find a simple example to analyze and figure out the rest. 👍
English
0
0
0
0
Ajax
Ajax@commial·
@spamv You can start from sigtree_init_module, which registers handlers for SIGTREE, SIGTREE_BM, SIGTREE_EXT. You'll see the first 5 bytes are "headers". +3 is what I interpret as the tree number, +5 a potential string, etc.
English
1
0
1
0
Ajax
Ajax@commial·
Documenting (part of) VDM, the Windows Defender signature format: github.com/commial/experi… Includes example of signature evasion and hourly updates diffing :)
Ajax tweet mediaAjax tweet mediaAjax tweet media
English
3
136
244
0
Marcelo
Marcelo@spamv·
@commial Thanks! Yes, I saw that they can store on or multiple tree signatures in each sigtree but I still didn’t figure out how to interpret the structure of a single one.
English
1
0
0
0
Ajax
Ajax@commial·
@spamv Unfortunately, I don't know for sure. You likely already noticed that SIGTREE entries are used to (suprise!) implement a signature tree. My guess is that SIGNATURE_TYPE_SIGTREE_BM is used to give some leaf. Also, BM_* are ref as attributes in analysis (MZ, JPG, events, ...)
English
1
0
1
0
Marcelo retweetledi
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com
English
32
1.1K
2.7K
0
Marcelo retweetledi
Jason Lang
Jason Lang@curi0usJack·
Github is revising its policies for offensive security related content. Time to make your voices heard! github.com/github/site-po…
English
14
207
342
0