OtterHacker Profile
OtterHacker

@OtterHacker

Followers
6K
Following
665
Statuses
704

Professional redteamer and malware development enthusiast ! I will share some tips and experiences. Look at my work here : https://t.co/cxLBvW7pcI

Joined August 2021
Don't wanna be here? Send us removal request.
@OtterHacker
OtterHacker
2 years
Hey ! I published a large part of my notes, and I hope you will find something new to learn in it. It goes from simple #OSCP notes to #Malware development (#COFFLoader, #ModuleStomping, #ReflectiveDLLInjection...).
9
159
448
@OtterHacker
OtterHacker
14 days
I was today old when I learnt that you can't use a ST on a DC that generated it. It seems to be a security feature to avoid replay attack. But if you activate Protected User on a domain with one DC you basically just locked you down but prevent attacks through SID History...
1
4
27
@OtterHacker
OtterHacker
14 days
@TontonTortue @iansus forwarded me this link
1
1
10
@OtterHacker
OtterHacker
28 days
I’m waiting for the moment where I will have to pentest applications developed with AI… I’m pretty sure it’s going to be a carnage…
0
0
5
@OtterHacker
OtterHacker
1 month
@gzobraJn Socks5 :)
0
0
1
@OtterHacker
OtterHacker
1 month
@zux0x3a Yes if I add to much sleep on the beacon the connections tends to timeout. But depending on the tools, extending the read/write timeout fix the problem but it makes the socks really slow ^^
1
0
2
@OtterHacker
OtterHacker
1 month
@EAGAIIN @httpyxel @C5pider @BlackAlpsConf Hey ! The process injection only work with admin privileges. The sleep obfuscation will always work. The difference is that: - with process injection you are adding a hook on a remote process => need SE DEBUG - with sleepobfuscation you are adding a hook on yourself
0
0
1
@OtterHacker
OtterHacker
1 month
@awwhwhasz Yes kinda like. I juste remappd the PE in memory and called the entrypoint :
1
0
4
@OtterHacker
OtterHacker
1 month
@d5fa4lt Right here
1
0
6
@OtterHacker
OtterHacker
2 months
Might be the most appropriate Xmas gift I had !
Tweet media one
0
0
6
@OtterHacker
OtterHacker
2 months
Finally took the time to implement a Ekko (documented by @C5pider) like sleep obfuscation on my beacon ! Thank's to all previous implementation it was quite easy. The technique might be well detected now but I found the main principle very pretty !
Tweet media one
1
3
93
@OtterHacker
OtterHacker
2 months
Finally implemented a SOCKS in my custom C2. I faced several challenged regarding constant polling and timeout due to the beacon sleep but I'm quite happy with the performances !
Tweet media one
5
7
139
@OtterHacker
OtterHacker
3 months
@techspence How would you pay the guy handling the detections ?
1
0
3
@OtterHacker
OtterHacker
3 months
Just trying to use LLM to automate PPTX and DOCX translation. It seems it needs some additional fine-tuning...
Tweet media one
0
0
2
@OtterHacker
OtterHacker
3 months
If you missed my talk at @BlackAlpsConf , you can find the slide deck in my usual repo ! The talk should be published in the end of the year !
1
13
44
@OtterHacker
OtterHacker
3 months
Hey ! I just saw that I didn't upload the slide deck... This is done now 😅
@OtterHacker
OtterHacker
6 months
I've published my #defcon32 workshop ! If you want to develop your own "Perfect DLL Loader", you will have all you need in it From the classic minimal loader to a fully featured one, this workshop in 6 steps is a journey inside the Windows internals !
0
1
6
@OtterHacker
OtterHacker
3 months
@zux0x3a @httpyxel @C5pider @BlackAlpsConf Nop, when the beacon sleeps no thread related to the beacon exists !
0
0
2