TGViewer
Channel Public Channel
Sec Note

Sec Note

@secnote

https://t.me/+BnJr9e6R2_YwMTVk
Subscribers
2.89K
Photos
141
Videos
9
Links
234

Showing posts older than #134 · Back to latest

Older Posts 19 shown
Post #128 1.39K
1. ThreadStackSpoofer by mgeeky
Overview: This tool demonstrates an advanced in-memory evasion technique that spoofs the thread call stack. It's designed to bypass thread-based memory examination rules, making it harder for analysts to detect injected shellcode within process memory.

- [ThreadStackSpoofer GitHub Repository]


2. CallStackSpoofer by WithSecureLabs
Overview: This proof-of-concept implementation demonstrates how to spoof arbitrary call stacks during system calls, such as NtOpenProcess. It's a more advanced technique that builds upon the concepts introduced in ThreadStackSpoofer.

- [CallStackSpoofer GitHub Repository]


3. Draugr by NtDallas
Overview: Draugr is a Cobalt Strike Beacon
Object File (BOF) template that facilitates the creation of synthetic stack frames, effectively spoofing the call stack during execution. It utilizes gadgets from KERNELBASE.DLL to achieve this

- [Draugr GitHub Repository]


4. LoudSunRun by susMdT
Overview: LoudSunRun is a technique that involves stack spoofing with synthetic frames. It calculates the total stack size of fake frames and adjusts stack arguments accordingly to obscure the true execution path.

- [LoudSunRun GitHub Repository]


5. BokuLoader by boku7
Overview: BokuLoader is a proof-of-concept Cobalt Strike Reflective Loader that aims to recreate, integrate, and enhance Cobalt Strike's evasion features. It combines various evasion techniques, including call stack spoofing, to achieve stealthy execution.

- [BokuLoader GitHub Repository]


https://dtsec.us/2023-09-15-StackSpoofin/

#Loader #callstack
  • 👾 5
Post #127 1.35K
WSASS
This is a tool that uses the old WerfaultSecure.exe program to dump the memory of processes protected by PPL (Protected Process Light), such as LSASS.EXE. The output is in Windows MINIDUMP format.


#lsass
  • 👾 4
Post #122 1.83K

Forwarded from GangExposed

The video shows 11 members of the Conti ransomware gang.

Dubai, UAE, February 2022

#GangExposed #Conti #Ransomware
  • 👾 11
  • 😁 1
Post #121 1.7K
DotnetNoVirtualProtectShellcodeLoader
load shellcode without P/D Invoke and VirtualProtect call.

How
This code leverages built-in .NET functionality to allocate an RWX memory region and overwrite a C# method with your own shellcode using the RuntimeHelpers.PrepareMethod(handle) method.

https://github.com/Mr-Un1k0d3r/DotnetNoVirtualProtectShellcodeLoader
  • 👾 2
Post #112 1.78K

Forwarded from encrypted.

White Matter. Vol 1. You Are (Not) Alone

Важный дисклеймер: Этот инструмент предназначен исключительно для образовательных целей и тестирования на системах, где у вас есть явное разрешение. Не используйте его для незаконного доступа к системам.
Автор инструмента не несет ответственности за ваши действия.

В этой части релиза я создал инструмент и бэкдор в одном лице, позволяющий взламывать SSH сервера и обычные системы со статическим IP-адресом, закрепляться в этих системах, перехватывать нажатия клавиш удаленно с помощью кейлоггера и прочие интересные возможности.

Ссылка на репо: https://github.com/lain0xff/White-Matter

#malware #offensive #white_matter
  • 👾 5
Post #111 1.59K
ChromElevator
Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.


🕷 #stealer
  • 👾 6
Post #110 1.76K
  • 👾 15
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →