TGViewer
r0 Crew (Channel) r0 Crew (Channel) @r0_crew · 8.96K subscribers
Post #2122 12.2K

Forwarded from Malware Research / RedTeam / News

New blog on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that identified by author in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan.

https://securityintelligence.com/x-force/being-a-good-clr-host-modernizing-offensive-net-tradecraft/

Proof-of-concept for the AMSI bypass and an implementation of a CLR memory manager is on GitHub. We can implement custom memory routines and track all allocations made by the CLR.

https://github.com/passthehashbrowns/Being-A-Good-CLR-Host

#redteam #net #clr
Security Intelligence Being a good CLR host – Modernizing offensive .NET tradecraft Learn how red teams can modernize their use of .NET assemblies using CLR customizations.
  • ⚡ 10
  • ❤ 8
  • 👍 5
More from @r0_crew
  1. Jan 1, 2025Happy New Year! May every binary reveal its secrets, every challenge find its solution, an…
  2. Nov 15, 2024Complete list of LPE exploits for Windows (starting from 2023) https://github.com/MzHmO/Ex…
  3. Sep 27, 2024Attacking UNIX Systems via CUPS, Part I CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, an…
  4. Sep 26, 20240-Click exploit in MediaTek Wi-Fi chipsets affects routers and smartphones / Exploiting (C…
  5. Sep 3, 2024Native function and Assembly Code Invocation https://research.checkpoint.com/2022/native-f…
  6. Aug 27, 2024Exploiting the Windows Kernel via Malicious IPv6 Packets (CVE-2024-38063) https://malwaret…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →