informationsecurity

Active Directory Canaries: Advanced Detection and Prevention of AD Enumeration

Active Directory Canaries is a detection primitive for Active Directory enumeration (or recon) techniques. It abuses the concept of DACL…

10 months ago

FACTION PenTesting Report Generation and Collaboration Engine

In the world of cybersecurity, where things change quickly, it's important to do thorough and fast penetration testing. Here comes…

10 months ago

XnLinkFinder v4.1 – A Comprehensive Guide To Discovering Endpoints And Parameters

This is a tool used to discover endpoints (and potential parameters) for a given target. It can find them by:…

10 months ago

Osquery-Defense-Kit : Enhancing Cybersecurity

Osquery queries for Detection & Incident Response, containing 250+ production-ready queries. ODK (osquery-defense-kit) is unique in that the queries are…

10 months ago

Coerced Potato Reflective DLL – Unveiling Privilege Escalation From NT Service To SYSTEM

Privilege escalation from NT Service to SYSTEM using SeImpersonateToken privilege and MS-RPRN functions. Heavily based Reflective Loader from Install Clone…

10 months ago

Exploiting CVE-2023-49103: A Python Script for Rapid phpinfo() Detection

PoC for the CVE-2023-49103 Overview This Python script is designed to efficiently process a large list of URLs to check…

10 months ago

InfoSec Black Friday Deals – “Friday Hack Fest” 2023 Edition

All the deals for InfoSec related software/tools this Black Friday / Cyber Monday. Researcher was a little late getting started…

10 months ago

AWS Kill Switch: Enhancing Cloud Security with Rapid Incident Response Tools

AWS Kill Switch is a Lambda function (and proof of concept client) that an organization can implement in a dedicated…

10 months ago

eBPF Tools: Revolutionizing System Monitoring with Advanced PTY Sniffing Techniques

This piece talks about eBPF tools and shows how they can be used to improve system monitoring by keeping track…

10 months ago

Dynmx Prototype: An Advanced API Call Trace Analysis Tool for Malware Detection

dynmx (spoken dynamics) is a signature-based detection approach for behavioural malware features based on Windows API call sequences. In a simplified way,…

10 months ago