🤖 Offensive Security - Platform Moderation Concerns
This article addresses the suspension of a legitimate offensive security professional's account, highlighting concerns about content moderation on social platforms. Such actions affect the community's ability to share and discuss security research.
Key Points:
• Legitimate offensive security professionals face account suspensions.
• This trend can hinder research sharing within the community.
🔗 Resources:
Image
🤖 Threat Intelligence - Observed Malicious Indicators
This post details several URLs and IP addresses observed as potentially malicious indicators, including short links, a Vercel application, and specific network endpoints.
Key Points:
• A short URL short.gy is noted, potentially leading to unwanted content.
• An nft-aridrop-demo.vercel.app domain is identified, often used for demonstration.
• An IP address 165.140.86.190 with a specific task endpoint is observed.
• The m365sync.com domain maps to 145.79.26.223, possibly a C2 server.
🔗 Resources:
• Short URL ↗ - Potential malicious short URL
• Vercel App ↗ - Demo application for airdrops
• Task Endpoint ↗ - Specific IP with task token
• M365 Sync ↗ - Domain mapping to a chainlence IP
Image
Image
💡 Offensive Security - WDigest Password Dumping Bypass
A new blog post introduces a technique to enable WDigest for plaintext password dumping from LSASS. This method is designed to avoid existing detection mechanisms.
Key Points:
• A new WDigest enablement technique is described.
• This allows dumping plaintext passwords from LSASS.
• The method is designed to bypass current detection strategies.
🔗 Resources:
• NeuralHax Blog ↗ - Blog post on WDigest bypass
🤖 Active Directory - ADIDNS RPC Internals Exploration
This content refers to an exploration into the internal mechanisms of Active Directory Integrated DNS (ADIDNS) RPC.
Key Points:
• The topic involves exploring ADIDNS RPC internals.
• This includes understanding Active Directory and DNS interaction.
🔗 Resources:
• Research Link ↗ - Details on ADIDNS RPC internals
🚀 Microsoft Tools - Diagnostic Data Viewer Utility
The Microsoft Diagnostic Data Viewer utility provides users with a way to inspect all telemetry data sent from their host system.
Key Points:
• Microsoft offers a tool to view diagnostic data.
• The utility shows all data transmitted from your host.
• Users can examine what telemetry their system sends.
🤖 Active Directory - LDAP "Code to Coverage" Series
This "From Code to Coverage" series discusses various aspects of LDAP Active Directory across multiple parts.
Key Points:
• The series covers LDAP Active Directory.
• It details aspects of "From Code to Coverage."
• Multiple parts explore the topic comprehensively.
🔗 Resources:
• LDAP Acti Part 1 ↗ - Active Directory coverage
• LDAP Acti Part 2 ↗ - Active Directory coverage
• LDAP Acti Part 3 ↗ - Active Directory coverage
• LDAP Acti Part 4 ↗ - Active Directory coverage
• LDAP Acti Part 5A ↗ - Active Directory coverage
• LDAP Acti Part 5B ↗ - Active Directory coverage
• LDAP Acti Part 6 ↗ - Active Directory coverage
✨ Exploit Development - EM Pulse Privilege Escalation
Research demonstrates a method for privilege escalation on a Google TV Streamer 4K by using an electromagnetic pulse to alter a single instruction.
Key Points:
• An EM pulse modified a single instruction.
• This granted uid 0 privileges from an unprivileged adb shell.
• The target system was a Google TV Streamer 4K.
🔗 Resources:
• Raelize Blog ↗ - Blog post on EM pulse exploit
Image
Image
⭐️ Support
If you liked reading this report, please star ⭐️ this repository and follow me on Github ↗, 𝕏 (previously known as Twitter) ↗ to help others discover these resources and regular updates.