TGViewer
Channel Public Channel
Sec Note

Sec Note

@secnote

https://t.me/+BnJr9e6R2_YwMTVk
Subscribers
2.89K
Photos
141
Videos
9
Links
234

Showing posts older than #39 · Back to latest

Older Posts 20 shown
Post #34
Sec Note pinned «The .NET Export Portal Via XPN A while back I published a post looking at how to craft a .NET assembly which exposes managed code via DLL exports, RunDLL32 your .NET. While working on some tooling recently I revisited this topic and wanted to know just why…»
Post #29 704
New blog on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that identified by author in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan.


Proof-of-concept for the AMSI bypass and an implementation of a CLR memory manager is on GitHub. We can implement custom memory routines and track all allocations made by the CLR.

https://github.com/passthehashbrowns/Being-A-Good-CLR-Host



Related Works and Resources
HostingCLR - Original implementation of CLR hosting

InlineExecute-Assembly - Original implementation of executing .NET assemblies as a BOF

Dealing with Failure: Failure Escalation Policy in CLR Hosts – This is the only real example I could find of offensive tradecraft using CLR Customizations when I was initially doing this research.

Hosted Pumpkin – A GitHub repository containing a proof-of-concept for implementing several CLR Customizations.

Shellcode: Loading .NET Assemblies From Memory – Donut was a great deal of help in wrangling all of the relevant data structures and definitions in C.

Customizing the Microsoft .NET Framework Common Language Runtime by Steven Pratschner – This is the definitive text on CLR Customizations. Simply a must-read if you have any interest in this area.





#redteam #net #clr #dotnet
  • 👾 2
Post #28 711
The .NET Export Portal
Via XPN
A while back I published a post looking at how to craft a .NET assembly which exposes managed code via DLL exports, RunDLL32 your .NET.


While working on some tooling recently I revisited this topic and wanted to know just why this works in the way that it does. After all, by now we’ve all seen the COM calls required to spin up the CLR, so what makes unmanaged exports so special?

#reverse
#dotnet
Post #22 715
Decrease Entropy of shellcode
The more predictable you are, the less you get detected - hiding malicious shellcodes via Shannon encoding


#shellcode
#evasion
  • 👾 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →