
cr3ghost
@cr3ghost • 8,118 subscribers
Curating security/vuln/exploit research, tools & free resources | Reverse engineering | Malware | Threat intel | Red/Blue Team | AI security | Game Hacking.
Shorts
Videos

A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. If you do anything with Active Directory, Entra ID, identity security, red teaming, or detection engineering and you're not reading his blog, you're behind. This is the researcher who found CVE-2025-55241, Global Admin in every Entra ID tenant in the world. No logs. No Conditional Access. Microsoft fixed it in 3 days. Creator of ROADtools, ROADrecon, roadtx, krbrelayx, mitm6, and ntlmrelayx contributions. His blog covers: PRT theft and phishing, Conditional Access bypass via resource exclusions, Temporary Access Pass lateral movement, Azure AD Connect credential dumping, Cloud Kerberos Trust abuse from Azure AD to on-prem, AD CS attack surface extended to Intune, SID filtering bypass across forest trusts (CVE-2020-0665), safer Zerologon exploitation, unconstrained Kerberos delegation abuse, ACL privilege escalation, and B2B trust hopping. Every post comes with tools, detection queries, and full attack chains. Bookmark the entire blog. Author: Dirk-jan #Infosec #RedTeam #DetectionEngineering
cr3ghost48,577 просмотров • 1 месяц назад

Citrix admins, your weekend plans just changed. CVE-2026-8452 was disclosed as a NetScaler memory overflow / DoS. Now watchTowr has dropped a Pre-Auth RCE PoC. Internet-facing edge appliances. No authentication. RCE. #ReverseEngineering #VulnerabilityResearch #Infosec
cr3ghost17,416 просмотров • 1 месяц назад

Over 90 binary exploitation challenges with detailed writeups. From your first buffer overflow to House of Orange. All free. All open source tools. Assembly fundamentals. Ghidra. GDB. pwntools. Stack overflows through every mitigation bypass: ASLR, PIE, NX, canaries, RELRO. ROP chains: static, dynamic, ret2csu, SROP, stack pivoting, partial overwrites. Format strings. Shellcoding. Then heap exploitation: double frees, use-after-frees, heap grooming, fastbin attacks, tcache poisoning, unsorted bin attacks, large bin attacks, unlink exploitation. House of Spirit. House of Lore. House of Force. House of Einherjar. House of Orange. Integer exploitation. FILE exploitation. Obfuscation and MOVfuscation. Custom architectures. Z3 and angr for symbolic execution. Automatic exploit generation. Every challenge has a writeup walking you from being handed the binary to writing the exploit. No IDA license needed. If you are learning binary exploitation, this is one of the most complete free courses that exists. Author: guyinatuxedo Demo Reference: #ExploitDevelopment #ReverseEngineering #InfoSec
cr3ghost23,184 просмотров • 1 месяц назад

SmartScreen bypassed. Mark of the Web removed. No Run Dialog. No PowerShell popup. Just a browser file upload. FileFix is a new ClickFix alternative. Browser file upload opens File Explorer. File Explorer address bar executes OS commands. cmd.exe spawns as a child of Chrome. The user thinks they are pasting a file path. Executables launched through File Explorer's address bar lose their MOTW attribute entirely. SmartScreen never triggers. Author: mr.d0x #Malware #Phishing #InfoSec
cr3ghost22,575 просмотров • 3 месяцев назад

Want to understand UEFI bootkits at a low level? Whether you're doing malware analysis, reverse engineering, exploit development, or kernel research, these are the resources that actually matter. First in-the-wild UEFI bootkit to bypass Secure Boot on fully patched Windows 11. Exploits CVE-2022-21894 (BatonDrop), enrolls attacker MOK keys, deploys a kernel driver and HTTP downloader. Sold for $5,000 on forums. by WeLiveSecurity UEFI firmware rootkit targeting VMware VMs. Design inspired by CosmicStrand, MoonBounce, and ESPecter. Injects into a UEFI driver firmware volume, hooks ExitBootServices, catches WinLoad.EFI, hooks OslArchTransferToKernel, then injects a stager into ACPI.SYS to reach kernel execution without triggering PatchGuard. Originally by Austin Hudson (@ilove2pwn_) who deleted his account. Mirrored here. Binarly's analysis of BlackLotus by Alex Matrosov. Reveals that BlackLotus's code is directly based on btbd's Umap project from 2020, same main function logic, same ImgArchStartBootApplication hook chain, identical trampoline code. Game hacking UEFI bootkit code combined with a publicly available Secure Boot bypass PoC became the first in-the-wild bootkit to defeat Secure Boot. Also covers the CVSS scoring problem, supply chain failures in UEFI revocation, and MokList NVRAM manipulation. by BINARLY🔬 The book. Covers everything from legacy MBR bootkits to modern UEFI implants, firmware rootkits, and Secure Boot internals. If you only read one thing on this list, make it this. by Alex Matrosov ESPecter. Real-world UEFI espionage bootkit found in the wild with roots back to 2012. Patches bootmgfw.efi on disk, hooks the boot chain, disables DSE by patching SepInitializeCodeIntegrity in the kernel. Deploys a keylogger and document stealer. by WeLiveSecurity Reverse engineering of kernel driver by IDontCode. Shows how the entire cheat is public code resold for six figures. Documents the win32kbase.sys vtable pointer swap for kernel function invocation, manual driver mapping using btbd's modmap, and communication via Can's NtConvertBetweenAuxiliaryCounterAndPerformanceCounter .data pointer hook. Credits both Can and btbd directly. by Back Engineering Labs One of the earliest public Windows UEFI bootkit PoCs. Patches winload.efi to disable DSE and load unsigned kernel drivers. Directly inspired EfiGuard. by legendary anti-cheat engineer Aidan Khoury Bootkitting Windows Sandbox. Patches bootmgfw.efi inside the sandbox VHDx to hook the boot chain, disable PatchGuard and DSE, and load unsigned drivers without a debugger attached. Built for kernel research and driver development. by Duncan Ogilvie 🍍 and Dylan Goods from secret club UEFI DXE driver that passively disables PatchGuard and DSE at boot time. Does not modify bootmgfw.efi on disk. Instead hooks EFI System Table LoadImage to intercept the boot chain in memory, then patches SepInitializeCodeIntegrity and KeInitAmd64SpecificState in ntoskrnl. Supports every EFI-compatible Windows x64 from Vista SP1 to Windows 11. by Mattiwatti DMA backdoor via PCIe FPGA. No software on the target machine at all. A Spartan-6 FPGA on a PCIe card reads and writes physical memory over DMA to inject code into the UEFI boot process before the OS loads. The hardware end of the escalation ladder. by Dmytro Oleksiuk 💥 [email protected] Popular in the game hacking community. UEFI manual mapper that maps unsigned drivers into kernel memory from the boot environment, bypassing DSE entirely. Binarly confirmed BlackLotus reused this project's code directly. by BTBD Another UEFI bootkit approach for manual mapping unsigned kernel drivers. Hooks ExitBootServices to patch the kernel in memory before execution. by Samuel Tulach UEFI mapper in the same lineage. by ekknod Many of these use the .data section function pointer hook technique pioneered by the legendary Can. Instead of patching code (which PatchGuard monitors), you overwrite function pointers stored in .data (which PatchGuard doesn't). Still widely used. Combining a Secure Boot bypass with the RedLotus UEFI Bootkit on Windows 11. Full demo. #ReverseEngineering #MalwareAnalysis #Infosec
cr3ghost12,734 просмотров • 1 месяц назад
Больше нет контента для загрузки