tgindex
Sec Note

Sec Note

Статистика
Последний пост
14 авг.
Последнее чтение
14 авг.
Постов за неделю
3
Всего постов
49
Тип
открытый
Язык
und
В каталоге с
13 авг.
Подписчики
2 217
+33 за 2 дн.
Сутки
+3
+0,14%
Неделя
 
Месяц
 
Просмотров на пост
1 947
40 постов
Вовлечённость
87,8%
к подписчикам
Постов в день
0,4
всего 49
Упоминаний
5
каналов
Охват размещения
оценка
1/24сутки в ленте
1 500
1/48двое суток
1 718
1/72трое суток
1 854

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • видео или голосовое, без подписи

  • 11 авг.1 692869

    🔓 Dumping NTLM Hashes from Windows Memory via forensics tools What can an attacker recover from a Windows memory image after gaining access to an endpoint? In my new blog, I explored: WinPmem → Volatility 3 → SYSTEM/SAM → NTLM #RedTeam #OffensiveSecurity

  • 10 авг.2 7431754

    گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسی اینجا قراره ریپورت‌هایی که منتشر میشه رو بررسی کنیم، تکنیک‌های جدید رو استخراج کنیم و درباره‌ی مشکلات فنی و چالش‌هایی که سر راه اجراست بحث کنیم. https://t.me/+drFBtbbrVDo5NjA0

  • 1 авг.1 5931696

    Archive gems, don't bookmark. #EDR

  • 27 июл.4 07511214

    видео или голосовое, без подписи

  • 27 июл.3 74211104

    Red Team Engineering 2026 Info : https://nostarch.com/red-team-engineering #redteam

  • 15 июл.1 83220

    видео или голосовое, без подписи

  • 15 июл.1 85420

    видео или голосовое, без подписи

  • 15 июл.1 83119

    видео или голосовое, без подписи

  • 15 июл.1 455520из cIub1337

    The EU just sanctioned the operators behind Lumma Stealer. “Daugn0” and “Lummaseller” have been officially designated for their roles in developing, distributing, and selling the LummaC2 infostealer. Also added: • BPH MediaLand LLC and its owner • Two members of Cyber Army of Russia Reborn • Bentley/Stern (CONTI ransomware) • Two members of GRU Unit 29155 The inclusion of the Lumma operators is particularly notable. Looks like the “lummakrysy” drama wasn’t entirely off the mark after all. cc g0njxa, Gi7w0rm https://eur-lex.europa.eu/eli/reg_impl/2026/1714/oj/eng Telegram ✉️ @club1337 X (Twitter) 🕊 @club31337

  • 13 июл.1 549934

    Passive Active Directory security enumeration via native ADSI/COM interfaces. No .NET. No PowerShell. No managed runtime. #ad

  • 13 июл.1 487818

    Persistence via Fake AMSI Provider | Playbook & Detection Strategies #persistence #amsi

  • 2 июл.2 024628

    Accelerating EDR Evasion with LLM-Driven Analysis #EDR #LLM

  • 1 июл.1 81639из vxunderground

    tl;dr really effective malware multi-staged, multiple programming languages, use as many dependencies as possible. AI making this easier to do. AVs struggling Historically, in regards to malware development, the end goal was minimalism. It was in your best interest to strip as many dependencies, shred the file size down, and make it position independent. I think, as of ... now ... we need to take a different approach. I think instead of stripping binaries, we (Red Team, Threat Emulation, malware developers) should intentionally introduce dependencies. I have witnesses two unique things in the malware landscape since the AI boom. 1. Increase in malware slop. I continue to see stagers which contain notes in them. This is not intentional and this does not "trick" the analyst. This is a colossal mistake on the malware developers part. However, despite it being slop, AI has made malware more diverse. I am seeing more and more malware in Lua, Node JS (including SEA and nexe), Java, and Python. I am seeing more and more malware doing inter-process communication across multiple programming languages. Of course all of these have existed prior to AI, but I am seeing an explosion in these languages. This also has resulted in malware researchers creating new tools to combat this malware diversity. 2. Anti-malware services struggling. When I encounter a binary that is a Node JS SEA blob (Electron JS .exe, self-contained using SEA), which extracts a .JS payload, which uses obfuscated Java or heavily obfuscated Lua, all of these languages require a VM (PVM, LVM, JVM, whatever) for interpretation. Thus, with heavy obfuscation and multistaging, static analysis fails and the heavy abstraction makes it difficult for traditional hooking or minifilters to be effective, in essence there is too much noise. Many of these payloads with heavy dependencies easily avoid static analysis and even some emulation systems because they fail to account for the necessary dependencies which are required to emulate it correctly. pic maybe related idk

  • 1 июл.1 389217

    New Stealit Campaign Abuses Node.js Single Executable Application #SEA #Nodejs #malware

  • 1 июл.1 5183

    SpotifyC2 — Cloud-Based Command Channel Research Execute commands through a Spotify playlist and receive command output through Telegram. #c2

  • 1 июл.2 4181169

    SpotifyC2 — Cloud-Based Command Channel Research Execute commands through a Spotify playlist and receive command output through Telegram. #c2

  • 30 июн.2 362761

    Accelerating EDR Evasion with LLM-Driven Analysis #EDR #LLM

  • 27 июн.1 653322

    AMSI/ETW Evasion for PowerShell, without patching amsi.dll, by manipulating the CLR/JIT and using a Tail Jump patch for ETW 🔥 #etw #amsi

  • 25 июн.1 519223из OrcaCyberWeapons

    We’re building a small community around binary security research, focused on things like: - Reverse Engineering - Binary Obfuscation / Deobfuscation - Exploit Development - Compiler / interpreters... - Malware Analysis - Binary Hardening research we also work on open source tools and experiments here: GitHub → BinaryHardening GitHub Discord → BinaryHardening Discord If low level stuff and weird binaries are ur thing, come join us Always happy to meet more RE people

Sec Note — tgindex