Post #287
1.56K
Channel Public Channel
SE Sec Note
@secnote
- Subscribers
- 2.88K
- Photos
- 141
- Videos
- 9
- Links
- 234
Showing posts older than #288 · Back to latest
Older Posts 19 shown
Post #286
1.42K
Greedeks/GTweak: Portable Tool for an Ideal Windows Setup 😁
What it does:
What it does:
- Activating Windows using HWID and KMS methods;
- Disabling Windows Defender, SmartScreen, Antimalware, VBS, and UAC;
- Disabling/pausing Windows updates and removing temporary update files;
- Disabling unused and unnecessary system services;
- Disabling keyloggers and telemetry for Windows, NVIDIA, and Intel;
- Disabling services and events related to the collection of user data;
- Disabling data collection tasks in the Windows Task Scheduler;
- Disabling unnecessary network protocols: Teredo, ISATAP, and IPv6;
- Disabling built-in Windows diagnostic tools and disk defragmentation;
- Disabling personalized ads and system banners in Windows, including SCOOBE;
- Disabling system notifications, recommendations, and tips in Windows;
- Blocking Microsoft's shadow domains that collect data via hosts and firewall;
- Uninstalling OneDrive and Microsoft Edge along with clearing all associated data and WebView2;
- Removing standard pre-installed UWP apps in Windows 10/11;
- Removing and disabling AI assistants: Cortana, Copilot, and Recall;
- Customizing the interface: changing themes, window settings, taskbar layout, and icons;
- Configuring keyboard and mouse settings: disabling key filtering, sticky keys, and pointer acceleration;
- Adjusting Windows settings and applying the ultimate performance power plan;
- Adjusting power settings for Realtek High Definition Audio drivers to fix sound delay;
- Viewing the hardware configuration and monitoring system components;
- Compressing and decompressing files and directories using NTFS to save space;
- Clearing RAM, temporary files, icon caches, and securely deleting the Windows.old folder;
- Executing custom scripts (.ps1, .cmd, .bat, .reg) with TrustedInstaller privileges.
- 😁 3
- 👍 2
Post #285
1.52K

Soheil Hashemi's Certified Azure Red Team Expert (CARTE) Review
A look at his journey to earning the CARTE certification.
https://www.soheilsec.com/certified-azure-red-team-expert-carte-review/
A look at his journey to earning the CARTE certification.
https://www.soheilsec.com/certified-azure-red-team-expert-carte-review/
- 🔥 12
- 👍 3
Post #284
1.36K
Post #283
1.37K
Forwarded from Order of Six Angles
YouTube Introduction to VM-Based Loaders A practical introduction to VM-based loader architecture for offensive security practitioners. This talk covers the core concepts behind bytecode-interpreted loaders: why they matter in the current EDR landscape, how they work under the hood, and what they…- 👾 4
- 🔥 2
Post #282
1.26K
Forwarded from Order of Six Angles

Парочка интересных моделей попалось:
The fast, uncensored llama.cpp build of the strongest SuperGemma text line
Для багхантинга веб
The fast, uncensored llama.cpp build of the strongest SuperGemma text line
Для багхантинга веб
- 🔥 6
Post #281
1.48K
Bring Your Own RWX Region DLL (BYORWXDLL)
There are a lot of places in OneDrive and .NET stuff, also browsers but they have some protection...
- 👾 6
- 🔥 5
Post #280
1.68K
Deeeeeeeep ETW Internals: Architecture, Hooking, Tampering, and Detection
#ETW #internals
X (formerly Twitter) kernullist (@kernullist) on X Security and anti-cheat researcher focused on Windows internals.
Advancing reliable detection and stronger system integrity.
https://t.co/1hoZxnzccW Kernullist published his Obsidian research notes.
#ETW #internals
- 👾 4
- 🔥 3
Post #278
1.44K


Adversarial Tradecraft:
Interactive slide deck covering operational security principles for authorized red team operations and penetration testing engagements.
Live site: hackinglz.github.io/tradecraft-training Repo: github.com/HackingLZ/tradecraft-training
Interactive slide deck covering operational security principles for authorized red team operations and penetration testing engagements.
Live site: hackinglz.github.io/tradecraft-training Repo: github.com/HackingLZ/tradecraft-training
- 👾 5
Post #277
1.77K
Post #276
1.49K
Forwarded from Life-Hack - Хакер

OPSEC-провалы
#opsec #полезное #redteam
Подборка случаев, от неприятных ошибок до громких провалов, заканчивавшихся утечками данных, деанонимизацией и раскрытием целых групп. Внутри статьи, видео и материалы судов. Полезно для изучения, чтобы не наступить на те же грабли и понять, где искать зацепки в своих расследованиях.
Ссылка на GitHub
LH | News | OSINT | AI
#opsec #полезное #redteam
Подборка случаев, от неприятных ошибок до громких провалов, заканчивавшихся утечками данных, деанонимизацией и раскрытием целых групп. Внутри статьи, видео и материалы судов. Полезно для изучения, чтобы не наступить на те же грабли и понять, где искать зацепки в своих расследованиях.
Ссылка на GitHub
LH | News | OSINT | AI
- 👍 3
Post #275
2.7K
SentinelInstaller_windows_64bit_v25_1_4_434.msi57.9 MB
Token:
eyJ1cmwiOiAiaHR0cHM6Ly9ldWNlMS0xMDkuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogImNkZWIxMGEwYmM4ZGUwMTU3ZjliZGRmNjdkMDJmOTE2NzE0NjMwNzEyNGIxNTlhYzcwZGRmYWI2OGZiYzEzNGEifQ==
#EDR
eyJ1cmwiOiAiaHR0cHM6Ly9ldWNlMS0xMDkuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogImNkZWIxMGEwYmM4ZGUwMTU3ZjliZGRmNjdkMDJmOTE2NzE0NjMwNzEyNGIxNTlhYzcwZGRmYWI2OGZiYzEzNGEifQ==
#EDR
- 👾 5
- 🔥 3
Post #274
7.01K

- 👾 5
- 🔥 3
Post #273
2.02K
Post #272
1.97K
Post #271
2.19K
Malware, Cats and Cryptography 2026-cocomelonc-bsideslux.pdf
Let me keep it short… use uncommon stuff for static
(here is my conference ┐( ∵ )┌)
chain things smart to get past behavior detection.
Post #270
2.07K
Forwarded from Malware, Cats and Cryptography
2026-cocomelonc-bsideslux.pdf5.6 MBBSides Luxembourg 2026 slides
#conference #malware #research #ai #programming #maldev #apt #hacking
#conference #malware #research #ai #programming #maldev #apt #hacking
Post #269
2.73K

TL;DR: Two command injection vulnerabilities exist in the Windows Explorer “Open PowerShell window here” context menu due to improper quoting and command injection through user-controlled folder paths. By creating folders with crafted names (e.g., folder; calc), an attacker can trigger arbitrary PowerShell command execution when a user uses Shift + Right-Click → Open PowerShell window here. One variant affects modern Windows 11 builds, while another existed since Windows 10 1703 (2017).
You can find the scenarios and the slides of the Insomni’hack 2026 talk in https://github.com/p0dalirius/Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus
- 👍 2
Post #268
2.39K

Good write-up on building a kernel-based EDR and understanding how Windows telemetry is actually implemented.
https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
Focus is on real detection primitives like:PsSetCreateProcessNotifyRoutine(Ex)for process lifecycle monitoringPsSetLoadImageNotifyRoutinefor image/DLL trackingObRegisterCallbacksfor process/thread handle filtering
kernel → user-mode communication via IOCTL + agent design
https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
- 👾 2

