WMIHACKER – A Bypass Anti-virus Software Lateral Movement Command Execution Tool

KitPloit - PenTest Tools!-- 中文版(Chinese version)Disclaimer: The technology involved in this project is only for security learning and defense purposes, illegal use is prohibited!Bypass anti-virus software lateral movement command execution test tool(No need 445 Port)Introduction: The common WMIEXEC, PSEXEC tool execution command is to create a service or call Win32_Process.create, these methods have been intercepted … Continue reading WMIHACKER – A Bypass Anti-virus Software Lateral Movement Command Execution Tool

Lock and Code S1Ep15: Safely using Google Chrome Extensions with Pieter Arntz

Malwarebytes Labs-- This week on Lock and Code, we discuss the top security headlines generated right here on Labs and around the Internet. In addition, we talk to Pieter Arntz, malware intelligence researcher for Malwarebytes, about Google Chrome extensions. These sometimes helpful online tools that work directly with the Google Chrome browser can pull off … Continue reading Lock and Code S1Ep15: Safely using Google Chrome Extensions with Pieter Arntz

Sensitive data exposure with Nuclei: The new big gun with exploit bullets

InfoSec Write-ups - Medium-- Hey my hacker buddies! I hope you are enjoying the WFH(if you have)/ your bounty days! I am not hunting a lot since a good couple of months and that’s the reason I was not active on medium. I got some bounties and I thought to share something with you guys. … Continue reading Sensitive data exposure with Nuclei: The new big gun with exploit bullets

How I hacked redbus [An online bus-ticketing application]

InfoSec Write-ups - Medium-- [I drafted this writeup 2 years ago. As it took a long time for the patch, posting it now]It was a usual fresh and sleepy monday morning . I reached my desk and checking mails.😴few minutes passed..☎️ My Phone rang..I thought thats a usual call from customer care. No. It was my mom (The only two … Continue reading How I hacked redbus [An online bus-ticketing application]

Chimera – PowerShell Obfuscation Script Designed To Bypass AMSI And Commercial Antivirus Solutions

KitPloit - PenTest Tools!-- Chimera is a (shiny and very hack-ish) PowerShell obfuscation script designed to bypass AMSI and antivirus solutions. It digests malicious PS1's known to trigger AV and uses string substitution and variable concatenation to evade common detection signatures.Chimera was created for this write-up and is further evidence of how trivial it is … Continue reading Chimera – PowerShell Obfuscation Script Designed To Bypass AMSI And Commercial Antivirus Solutions