Последние посты

Source Byte
15 сент., 11:59
We were able to identify 6 Iran related underground activity , but yet shared POC of "JumpJump" vpn incident is unknown to us. It will be very helpful to help us cluster this activity by sending more details in our channel DM :)also you don't need to pay for VPN !!! Unredacted group provide high quality free solutions to anyone who need free access to internet :) Try it now : https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/
Source Byte
22 авг., 13:10
Building Something EDR-like with Rust×eBPFhttps://speakerdeck.com/sunlife3/rustxebpf-de-edr-ppoi-mono-o-tsukuru
Source Byte
20 авг., 14:52изменён
https://x.com/WuBlockchain/status/2090396627257503764How the Tornado Cash Lawsuit Was Won and Why It Matters https://youtu.be/4BfiRMGs6Hg?si=mu3-IyMMcFLK61Jq


Source Byte
19 авг., 11:45
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF #CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023.


Source Byte
19 авг., 11:43
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF #CVE-2023-2156 (“Route of Death”) is a Linux kernel vulnerability that was believed to only lead to a DoS attack, and was considered patched in April 2023. However, Nebula Security discovered a bypass of the patch and found that it is actually exploitable and can lead to LPE on any Linux distribution that has IPv6 and namespaces enabled. This writeup covers the technical details of the exploit.https://nebusec.ai/research/cve-2026-43501-route-of-root/
Source Byte
18 авг., 05:44
переслано из @secnote
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?If the goal is to obtain local account credential material, SAM might be enough for what we need.The point is simple: choose the technique based on the objective, not based on how complicated it is.#EDR #SentinelOne
Source Byte
14 авг., 17:03



Source Byte
12 авг., 18:47
https://github.com/FSECDEV/LEAKSFORUMS/blob/main/README.md
Source Byte
12 авг., 18:45
https://github.com/FSECDEV/LEAKSFORUMS/blob/main/README.md


Source Byte
12 авг., 14:39изменён
i will waste coming holiday on this 😂


Source Byte
12 авг., 14:29изменён
credits : Dancho Danchev
Source Byte
11 авг., 14:38
переслано из @secnote
🔓 Dumping NTLM Hashes from Windows Memory via forensics tools What can an attacker recover from a Windows memory image after gaining access to an endpoint? In my new blog, I explored: WinPmem → Volatility 3 → SYSTEM/SAM → NTLM#RedTeam #OffensiveSecurity


Source Byte
10 авг., 17:55
переслано из @secnote
گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسیاینجا قراره ریپورتهایی که منتشر میشه رو بررسی کنیم، تکنیکهای جدید رو استخراج کنیم و دربارهی مشکلات فنی و چالشهایی که سر راه اجراست بحث کنیم. https://t.me/+drFBtbbrVDo5NjA0
Source Byte
8 авг., 05:12изменён
بعضیها فکر میکنند همین که روی کلاینت Sysmon نصب شد، دیگر از این به بعد حتی اگر کاربر عطسه هم بکند، لاگش میاد،
Source Byte
29 июл., 10:14
FirmBurn:How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting
Source Byte
29 июл., 10:13
FirmBurn:How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting Dell EMC storage systems.https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/


Source Byte
28 июл., 04:25
переслано из @secnote

Source Byte
28 июл., 04:25
переслано из @secnote
Red Team Engineering 2026Info : https://nostarch.com/red-team-engineering#redteam


Source Byte
27 июл., 08:52
ODR: Internals of Microsoft's New Native MCP Registrationhttps://www.originhq.com/research/msft-odr-mcpOrigin TechnologyODR: Internals of Microsoft's New Native MCP Registration | Origin TechnologyReverse engineering Odr.exe reveals how Windows On-Device Registry runs MCP, via undocumented COM interfaces, a SQL-backed consent database, and ETW audit.
Source Byte
27 июл., 05:12
Cognitive_Reframing_Revised_Evidence_Study.docx
