|
You are here |
muffsec.com | ||
| | | | |
scriptjunkie.us
|
|
| | | | | [AI summary] The post details eight specific Windows features and services, such as SCM and Task Scheduler, that can be exploited to perform authenticated remote code execution on networked systems. | |
| | | | |
bugslasher.net
|
|
| | | | | Maybe you thought when you read this title: "well it's kind of easy, I just have to attach any debugger to my running service". And you're definitely right. But sometimes you have to debug the verybeginningof your service (just after the "Start" control), or even before, when the main() function has just started. Or you're... | |
| | | | |
oddvar.moe
|
|
| | | | | TL;DR - Found a technique to execute any binary file after another application is closed without being detected by Autoruns.exe. - Requires administrator rights and does not belong in userland. - Can also be executed from alternate data streams - Plant file on disk and run these commands to create persistence that triggers everytime someone... | |
| | | | |
objective-see.org
|
|
| | | [AI summary] The text discusses various malware and attack frameworks, including CloudIOP, CloudIOP, CloudIOP, CloudIOP, CloudIOP, and CloudIOP. It provides details on their infection vectors, persistence mechanisms, capabilities, and indicators of compromise (IoCs). The text also covers the Alchimist attack framework and its cross-platform payloads, such as Insekt for macOS. The summary highlights the methods used by these malware to infiltrate systems, maintain persistence, and execute malicious activities, along with the specific IoCs associated with each threat. The text emphasizes the importance of monitoring for these indicators and implementing security measures to mitigate the risks posed by these threats. | ||