TGViewer
Channel Public Channel
Offensive Xwitter

Offensive Xwitter

@offensivetwitter

~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://t.me/OffensiveTwitter/546
Subscribers
21K
Photos
915
Videos
49
Links
2.1K

Showing posts older than #3049 · Back to latest

Older Posts 17 shown
Post #3047 9.24K
😈 [ Aurélien Chalot @Defte_ ]

Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳

🐥 [ tweet ]
  • 🔥 14
  • 👍 5
Post #3046 7.27K

Forwarded from Standoff 365

Успей заявить о себе на Standoff Talks 16 октября 🔥

Call for papers все еще открыт. Если у тебя есть крутые кейсы по OSINT, багбаунти, пентесту, редтиму или на темы TI, threat hunting, работе SOC, то это твой шанс поделиться опытом с элитой практической безопасности. Выбирай удобный формат — 40 или 10 минут — и присылай заявку!

⁉️ Важно! Мы ждем твоих докладов до 26 сентября. То есть, у тебя осталась неделя, чтобы подать заявку и стать спикером ивента.

И напоминаем, что на митап нужно не забыть зарегистрироваться. Тем, кто уже зарегистрировался мы начнем рассылать подтверждения со следующей недели!

Не упусти шанс поучаствовать в таком крутом ивенте!
  • 👍 4
Post #3045 6.46K
😈 [ dis0rder @dis0rder_0x00 ]

New tool drop! Let me show you Obex:

🔗 https://github.com/dis0rder0x00/obex

Spawn a process and block unwanted DLLs from loading (in user mode).

Example: spawn powershell without "amsi.dll" for an easy amsi-less experience :)

🐥 [ tweet ]
  • 🔥 11
  • 😁 5
Post #3038 5.94K
😈 [ Kurosh Dabbagh @_Kudaes_ ]

I just released MFTool, an NTFS parser that builds an in-memory map of a volume, allowing you to:
- Read any file without opening a handle
- Get the contents of locked/deleted files (registry hives, pagefile.sys, etc)
- Perform fast, in-memory searches across the entire disk

Although direct access to disk is not new at all, especially when it comes to forensics, I think this approach could be useful in a number of contexts during a RT engagement.

🔗 https://github.com/Kudaes/MFTool

🐥 [ tweet ]
  • 🔥 13
  • 👍 2
Post #3037 7.38K
😈 [ Tijme Gommers @tijme ]

Exciting times. I'm publishing Dittobytes today after presenting it at @OrangeCon_nl !

Dittobytes is a true metamorphic cross-compiler aimed at evasion. Use Dittobytes to compile your malware. Each compilation produces unique, functional shellcode.

🔗 https://github.com/tijme/dittobytes

🐥 [ tweet ]
  • 🔥 14
  • 👍 3
Post #3034 6.42K
😈 [ spencer @techspence ]

A quick and easy way to find services with unquoted service paths is to open up PowerShell and run the following:

Get-WmiObject win32_service | select Name,PathName,StartMode,StartName | where {$_.StartMode -ne "Disabled" -and $_.StartName -eq "LocalSystem" -and $_.PathName


🐥 [ tweet ]
  • 👍 21
  • 🍌 7
Post #3031 7.61K
😈 [ Two Seven One Three @TwoSevenOneT ]

"clipup.exe" in System32 is very powerful. It can destroy the executable file of the EDR service 😉 Experimenting with overwriting the MsMpEng.exe file.

Proactively creating processes with Protected Process Light (PPL) protection will give you more opportunities to abuse these processes. Detailed article:

🔗 https://www.zerosalarium.com/2025/08/countering-edrs-with-backing-of-ppl-protection.html

🐥 [ tweet ]
  • 🔥 12
  • 😁 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →