![OtterHacker Profile](https://pbs.twimg.com/profile_images/1432380616469790725/abasMhht_x96.jpg)
OtterHacker
@OtterHacker
Followers
6K
Following
665
Statuses
704
Professional redteamer and malware development enthusiast ! I will share some tips and experiences. Look at my work here : https://t.co/cxLBvW7pcI
Joined August 2021
Hey ! I published a large part of my notes, and I hope you will find something new to learn in it. It goes from simple #OSCP notes to #Malware development (#COFFLoader, #ModuleStomping, #ReflectiveDLLInjection...).
9
159
448
@zux0x3a Yes if I add to much sleep on the beacon the connections tends to timeout. But depending on the tools, extending the read/write timeout fix the problem but it makes the socks really slow ^^
1
0
2
@EAGAIIN @httpyxel @C5pider @BlackAlpsConf Hey ! The process injection only work with admin privileges. The sleep obfuscation will always work. The difference is that: - with process injection you are adding a hook on a remote process => need SE DEBUG - with sleepobfuscation you are adding a hook on yourself
0
0
1
Finally took the time to implement a Ekko (documented by @C5pider) like sleep obfuscation on my beacon ! Thank's to all previous implementation it was quite easy. The technique might be well detected now but I found the main principle very pretty !
1
3
93
If you missed my talk at @BlackAlpsConf , you can find the slide deck in my usual repo ! The talk should be published in the end of the year !
1
13
44
Hey ! I just saw that I didn't upload the slide deck... This is done now 😅
I've published my #defcon32 workshop ! If you want to develop your own "Perfect DLL Loader", you will have all you need in it From the classic minimal loader to a fully featured one, this workshop in 6 steps is a journey inside the Windows internals !
0
1
6
@zux0x3a @httpyxel @C5pider @BlackAlpsConf Nop, when the beacon sleeps no thread related to the beacon exists !
0
0
2