Simple Trick: Code behavior detected by Anti-virus and Some AVs via Sleep/timer trick in C#
Video: youtube.com/watch?v=hmzKun6eFh

#Bypassing #penesting #redteaming #bypassav #evasion #inmemory #redteam #pentest

Last updated 2 years ago

KASPERSKY and ...
NativePayload_PE1/PE2 also some New code Which Callback Function API integrated to Delegation Method [Technique D] & Bypassing some AVs, source code available in my Github [github.com/DamonMohammadbagher] but those two new Codes "NativePayload_AsynASM.cs + NativePayload_ASM3.cs" will share in the future but you can see source code in Video ;D

#bypassed #penesting #redteaming #bypassav #evasion #inmemory #redteam #pentest

Last updated 2 years ago

KASPERSKY again ;D
with Native API you can change Memory very simple and i tested simple c# code to Convert payload before running payload also after running payload with delay so In-memory every 60 secs only once RAW payload will run in memory and this code still needs to test but i did not have any error in Server-side or client-side and commands worked very well but still needs to work on this code (this code just was for test),
btw code was not Detected by Kaspersky so i can say KASPERSKY Bypassed again ;D
anyway or in-memory can help you sometimes ;)

#bypassed #process #inmemory #cobaltstrike #encrypting #obfuscating #penesting #redteaming #bypassav #evasion #redteam #pentest

Last updated 2 years ago

hobs · @hobs
408 followers · 761 posts · Server mstdn.social

Oops. Wrong app. Was taking notes on the Christmas Eve interview with (@CamSaysThis). BTW, he's looking for work in

#CyberSecurity #penesting #Kilobit #darknetdiaries

Last updated 2 years ago