sn🥶vvcr💥sh
@snovvcrash
Followers
11K
Following
5K
Statuses
837
Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of Pentester’s Promiscuous Notebook (PPN) :: He/him :: Tweets’re my pwn 🐣
(ノ ˘_˘)ノ ζ|||ζ ζ|||ζ ζ|||ζ
Joined January 2017
RT @ShitSecure: Tired of using ts::multirdp, because Mimikatz is a nogo nowadays and get's flagged anyway most of the time? 🧐 Well, here i…
0
118
0
RT @hacker_ralf: This is C2 I decided to write publicly. If you are interested, I hope for feedback) I am fixing version 0.1 ... https://…
0
68
0
RT @ptswarm: 🎮 Xbox 360 security in details: the long way to RGH3. Read the exclusive story about the chipless and reliable Xbox 360 moddin…
0
14
0
That was not a straight forward one to port to cross-compilation & PIC format as well as deal with some module stomping injection pitfalls, but this @passthehashbrwn’s trick is cool as hell 🔥 Definitely NOT yet another byte patch 😅
New blog from me on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that I identified in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan.
2
6
92
RT @passthehashbrwn: New blog from me on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a nove…
0
142
0
RT @orange_8361: The detailed version of our #WorstFit attack is available now! 🔥 Check it out! 👉 cc: @_splitline_
0
212
0
RT @eliran_nissan: I am excited to share with you my latest research - "DCOM Upload & Execute" An advanced lateral movement technique to up…
0
243
0
@unsigned_sh0rt @synzack21 I’ve also thought about it, but I don’t think we can build such a generic wordlist that will be applicable in different networks. But if we talk about a particular network then yes, sometimes it’s enough to get a single hostname and then iterate over the predictable part of it 👍🏻
1
0
3
@al3x_n3ff @stratosberry @Disgame_ Fun fact, by the way, that we don’t actually need to implement any new modules - md5($pass, $salt) is already there 😅
1
2
8
@stratosberry @al3x_n3ff @Disgame_ Not possible, unfortunately. Cannot be pre-computed because of the salt :(
1
0
1
RT @ptswarm: 🎤✨ Our security researcher, Konstantin Polishin, presented “Red Team Social Engineering 2024: Initial Access TTP and Project E…
0
40
0
RT @_JohnHammond: Supply chain malware from an infected game mod 🤯😱 Long-form reverse engineering and a WILD ride: Binary Ninja, x64dbg, 01…
0
53
0