by frank | Oct 25, 2019 | AV, Red team, Security, Windows
Reading Time: < 1 minute For academic purpose only.The used of some functions can trigger singature based Anti Virus detection. Example : SystemFunction032 or SamEnumerateUsersInDomain used in same particular programs.in this example let’s try to hide the...
by frank | Oct 23, 2019 | AV, Red team, Security, Windows
by frank | Sep 19, 2019 | Palo Alto, Red team, Security
Reading Time: < 1 minute If you see files likes below = NO PANIC ! zzzz346468454.txt !!!!4873487.doc XORXOR131395328.pem zzzzz1128386401.png ZZZZZ4032929292.pptx !!!!!28748750874.pst !!!!!195855848565.bmp XORXOR394587587.pdf You are probably...
by frank | Sep 3, 2019 | Red team, Security, Windows
Reading Time: < 1 minuteVery interesting article and tool from Fireeye...
by frank | Aug 13, 2019 | Palo Alto, Red team, Security, Windows
Reading Time: < 1 minuteWMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List Example Windows ATP (Advanced Threat Protection) will come up as “Windows Defender”. To know if ATP is installed check reg...
by frank | Aug 12, 2019 | Red team, Security, Windows
Reading Time: 2 minutes Official Doc : https://github.com/gentilkiwi/mimikatz/wiki/module-~-sekurlsa Dump memory of LSASS : Don’t forget you need to be admin to be able to do it. with ProcDump from Sysinternals : procdump.exe -accepteula -ma...
Recent Comments