Setting Up a Detection Lab

Setting Up a Detection Lab

When doing an engagement sometimes one would need to test a payload or an attack vector before deploying it. Watching how an operating system logs different events or how security solutions detect certain payloads can be valuable information for a red teamer/penetration tester. An example that happened was gained credentials to MSSQL, and the MSSQL…

Malware Development

Malware Development

Work in Progress Courses SEKTOR7 Institute EvasionEDR By Matt Hand Sources URL Description Category HellShell GitHub repository Penetration Testing Exploit writing tutorial on Exploit Development website Cybersecurity AtlasLdr GitHub repository Malware Analysis Article on obfuscating C2 during Red Team engagement Red Teaming DefenderCheck GitHub repository Security…

C# – Basics and examples

C# – Basics and examples

C# Basics Data Types C# provides a number of built-in data types, including integers, floating-point numbers, booleans, and characters. Here are some examples: In this code, we declare and initialize variables of type int, float, bool, and char. The int and float types are used for storing numerical values, while the bool type is used…

AV Evasion 101: Essential Techniques and Concepts

AV Evasion 101: Essential Techniques and Concepts

Source Good tools Malware forums/channels/discord Test payload against AV Defcon – Writing custom backdoor payloads with C# GitHub – mvelazc0/defcon27_csharp_workshop: Writing custom backdoor payloads with C# – Defcon 27 Workshop Step by Step for obfuscating code AV Evasion MindMap – From Start to finish (AV) Anti-Virus – The Hacker Recipes General AV Evasion cheatsheet Check…

Python Notes and Examples

Python Notes and Examples

Here are my notes from different courses I’m taking. Courses and resources Notes from ‘Learn Python & Ethical Hacking From Scratch‘ Lecture 1 – MAC Address Changer Change MAC address using subprocess Script upgrade using variables Input from user Handling user input The above example is not a secure way as…

Active Directory – Notes, Methodology, Cheatsheet

Active Directory – Notes, Methodology, Cheatsheet

These are my notes from the Active Directory networks at TryHackMe, as well as notes from other sources. Inspo: Work in progress References Matrix Impacket – SecureAuth Name Explanation Tools/attack example Unconstrained delegation Allows a service to delegate user credentials to any service on any computer. Exploiting unconstrained delegation involves accessing services running with SYSTEM…