the grugq's newsletter

Subscribe
Archives
September 10, 2024

September 10, 2024

September 10, 2024

Read this as the Hall of Meat pic.twitter.com/9Xza91h52M

— Classical Studies Memes for Hellenistic Teens (@CSMFHT) September 9, 2024


My @OrangeCon_nl talk is live!

Elevate your knowledge: From COM Object Fundamentals To UAC Bypasses.

A 25-minute crash course covering Tokens, Privileges, UAC, COM, and ultimately bypassing UAC!https://t.co/H1VZJdBzTZ pic.twitter.com/1NZEFUQ43K

— Tijme Gommers (@tijme) September 9, 2024

I've also published the source code & compiled binaries: https://t.co/DtiJVQb1Ll

— Tijme Gommers (@tijme) September 9, 2024


Do you like ZSH, SOCKS proxies and Impacket? Then you might want to check this out: https://t.co/XN5iQpzHYG pic.twitter.com/0mX5oWzGMd

— Daniel (@0x64616e) September 9, 2024


My maldev works and practices:

+ Ekko (Sleep Obfuscation By @C5pider): https://t.co/DPWiWXByS8

+ BloatedHammer(API-Hammering By @rad9800):https://t.co/7DSitj7iDh

+ Encryfer-X (Ransomware Project):https://t.co/WxY7nGTQeJ

+ Info Stealer Malware: https://t.co/auVRkULMGT

+…

— Smukx.E (@5mukx) September 9, 2024


Schools need to stop teaching kids malware is like, 'trojans', and 'worms', etc. It's not 1996 anymore.

New malware types:
- Ransomware
- Loaders
- Information Stealers
- Piles of shit that doesn't work
- RATs

— vx-underground (@vxunderground) September 9, 2024


Havoc is a modern and malleable post-exploitation command and control framework, created by @C5pider https://t.co/TXUriSDPkg pic.twitter.com/xG4kvgHK1U

— 7h3h4ckv157 (@7h3h4ckv157) September 9, 2024


TIDRONE APT targets drone manufacturers in Taiwan https://t.co/4stpPz0zfQ

— Nicolas Krassas (@Dinosn) September 9, 2024


#RIP dad 💔 https://t.co/YXpFoBb2Ua

— Mark Hamill (@MarkHamill) September 9, 2024


“Sweden's justice minister has warned that it could take a decade or even longer to combat Sweden's violent crime epidemic, as immigrant drug gangs infiltrate courts, police and prisons.” It's hard for me to even comprehend what I just read.

The minister also added that… pic.twitter.com/mmnupgXzEM

— Lukasz Olejnik (@lukOlejnik) September 10, 2024


#tools#OpSec#Red_Team_Tactics
1. Infiltrax - post-exploitation tool to capture screenshots, retrieve clipboard contents, log keystrokes, and install AnyDesk for persistent remote accesshttps://t.co/ZYyubRaEjp
2. XPost - Post Exploitation Tool for High Value Systems…

— Clandestine (@akaclandestine) September 9, 2024


Why GitHub Actually Won

How GitHub actually became the dominant force it is today, from one of it's cofounders.


#ElasticSecurityLabs is introducing HexForge, our tool that enhances #IDAPro with manipulation capabilities built into the hex and disassembly views. HexForge makes it easy to copy and patch binary data and currently supports RC4, AES, ChaCha20, and XOR: https://t.co/22Fo38kayR

— Elastic Security Labs (@elasticseclabs) September 3, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X