Cool feature coming soon to Brute Ratel 1.4 based on this project:
github.com/D1rkMtr/FilelessRem
“…can use…any tool written in Clang/GCC in the memory of your own payload”. That would be a huge win because having to rewrite every BOF to be compatible with BRC4 is a gigantic pain and effectively eliminates one of the biggest benefits to BOFs…reuse.

#bruteratel #brc4 #bof

Last updated 2 years ago

Kevin · @CyberThreat
28 followers · 14 posts · Server infosec.exchange

Researchers at Proofpoint warn the commercial framework is likely to be utilized by threat actors looking for and alternatives.

proofpoint.com/us/blog/threat-

#nighthawk #pentesting #cobaltstrike #brc4

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
218 followers · 112 posts · Server infosec.exchange

RT @NinjaParanoid@twitter.com

The aim of red team should always be to help the blue team and improve them. Thus along with the release blog of v1.3, I will be releasing detections till v1.2.9. Yara rules along with a detailed guide on detection and evasion will be available by EOD. Stay Tuned!

🐦🔗: twitter.com/NinjaParanoid/stat

#brc4

Last updated 2 years ago

Taylor Parizo · @taylorparizo
85 followers · 46 posts · Server infosec.exchange

From Chetan Nayak (Brute Ratel C4 author):
"The aim of red team should always be to help the blue team and improve them. Thus along with the release blog of v1.3, I will be releasing detections till v1.2.9. Yara rules along with a detailed guide on detection and evasion will be available by EOD. Stay Tuned!"

A nice change from C2 authors that I'm not sure I've seen before. This will be a fun cat and mouse game of who can evade rules.

#brc4 #yara #threatintel #malware

Last updated 2 years ago