Just Another Blue Teamer · @LeeArchinal
128 followers · 193 posts · Server ioc.exchange

Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as . They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like , , and , they also rely on abusing , or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using , , or to download tools, and accessing process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and !

#powershell #certutil #bitsadmin #Lsass #happyhunting #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #readoftheday #flaxtyphoon #ChinaChopper #metasploit #mimikatz #lolbins

Last updated 1 year ago

JM ☠️ · @jmamblat
333 followers · 220 posts · Server infosec.exchange

“New PostDump version include C# / .NET implementation of the famous NanoDump's NanoDumpWriteDump function, which permit to dump most important modules only”
github.com/post-cyberlabs/Offe

#Lsass #redteam #offensivesecurity #cybersecurity #infosec

Last updated 2 years ago

Matt "msw" Wilson · @msw
2350 followers · 1004 posts · Server mstdn.social

"AWS announces Credential Guard support for Windows instances on Amazon EC2"

Protect those secrets!

An OS like has a hard time doing it without based security, provided by a like the one found in the .

aws.amazon.com/about-aws/whats

#pth #passthehash #ActiveDirectory #Security #AWS #nitrosystem #Hypervisor #virtualization #Windows #Lsass

Last updated 2 years ago

JM ☠️ · @jmamblat
308 followers · 170 posts · Server infosec.exchange

Some serious work from folks at Elastic Security: “Silhouette is a POC that mitigates the use of physical memory to dump credentials from .”
github.com/elastic/Silhouette

#Lsass #cybersecurity #infosec #redteam #blueteam

Last updated 2 years ago

abyssal_dk · @abyssal_dk
33 followers · 74 posts · Server infosec.exchange

Outil simple pour effectuer un vidage de mémoire LSASS en utilisant quelques techniques pour éviter la détection.

github.com/post-cyberlabs/Offe

#redteam #Lsass

Last updated 2 years ago

JM ☠️ · @jmamblat
280 followers · 136 posts · Server infosec.exchange
Daru003 · @daru003
35 followers · 78 posts · Server infosec.exchange
acrypthash👨🏻‍💻 · @acrypthash
250 followers · 129 posts · Server infosec.exchange

November patch Tuesday causes memory leaks and forces reboot 👀

#Lsass

Last updated 2 years ago

abyssal_dk · @abyssal_dk
18 followers · 40 posts · Server infosec.exchange

Techniques intéressantes mais tjs bloqué par l'antivirus :sadglasses:
kaluche.github.io/posts/2020/0

#pentest #Lsass

Last updated 2 years ago