I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-)
github.com/amlweems/xzbot
Here is my latest, DropSpawn. This is a CS BOF used to spawn additional beacons via a little-known DLL hijacking method that I posted about ~2 months ago. Use as an alternative to process injection and force most any System32 exe to load an arbitrary DLL github.com/Octoberfest7/D…
Reverse Engineering a #CobaltStrike#malware sample and extracting C2's using three different methods.
We'll touch on #cyberchef, #x64dbg and Speakeasy from fireeye to perform manual analysis and emulation of #shellcode.
A (big) thread ⬇️⬇️
[1/23]
1 month to @PentesterLab giveaway!
To celebrate the 230k followers, I’m giving 1 month to PentesterLab. RT this tweet and I will randomly choose the winner in 48 hours.
🎅🎄Xmas #GIVEAWAY n. 3️⃣🎄🎅
Prize:
Limited Edition #sticker & #mask 😷
Rules:
✅ Follow @whid_ninja
✅ Retweet this post
Deadline in 48h ⏰ on 25/12
Everyday a new #GIVEAWAY 🔥
512 Followers 378 FollowingWho has access to what, how & why? Make digital transformation a success by securing transition to the Cloud with @Brainwave_GRC. #CyberSecurity #PAM #SoD #IGA
18K Followers 720 Following📺 La télévision locale #illeetvilaine
➡️ Canal 35 de la TNT et 30 sur les box
📸 Insta : TVRlachaine
🖥 YouTube : TVR la chaîne
📱 Facebook : TVR la chaîne
698 Followers 445 FollowingToute l'actualité en #Bretagne, #Normandie et #PaysdeLoire grâce au bureau de #FranceTV à #Rennes avec @c_wormser @sabinguy @thomaspaga @beaudouinmath
31K Followers 2K FollowingConsultant en risques internationaux (armements, nucléaire, agriculture), historien, officier de réserve. Mes tweets n'engagent que moi !
6K Followers 22 FollowingVIGINUM est le service technique et opérationnel de l’État chargé de la vigilance et de la protection contre les ingérences numériques étrangères.
4K Followers 147 FollowingA #SOCplatform boosted by #AI and #threatintelligence, combining #SIEM, #SOAR, #Automation in a single solution. Used by End-users, MSSP and APIs
137K Followers 84 Following⚔️ The official page of Benoît Saint Denis @UFC Lightweight Fighter 🇫🇷 📥 For requests or business inquiries : [email protected]
2K Followers 89 FollowingCompte officiel du Commandement Terre Europe (CTE)/French land forces HQ-Europe.
Actualités des missions des forces terrestres de l'@armeedeterre en Europe.
2K Followers 755 FollowingUnix and Open Source geek, with a soft spot for embedded systems.
Posts now private, following Musk's decision to nullify blocking, but follow requests welcome.
7K Followers 77 FollowingProfessional redteamer and malware development enthusiast ! I will share some tips and experiences. Look at my work here : https://t.co/cxLBvW7pcI
89K Followers 75 FollowingHi! I'm Dave Plummer. You might remember me from such Windows components as Task Manager, Windows Pinball, Calc, ZIPFolders, Product Activation, etc. Cheers!
19K Followers 536 FollowingThreat Hunting & DFIR, Hacker, Geek, DEF CON & Black Hat CFP Review Board Member, DEF CON Contest/Events/Demo Labs Dept. Head, Black Hat Staff, DC801 Founder
89K Followers 910 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
34K Followers 567 FollowingOfficial Twitter page of the 780th MI Brigade (Cyber). The Army's only offensive cyberspace operations brigade (following, retweets and links ≠ endorsement).
24K Followers 1 Following#NosArtisansOntDuTalent ont vraiment beaucoup de talent !
Attention aux #artisans que vous prenez pour vos #travaux !
90% des photos sont de nos expertises !