MalDev Academy's banner
MalDev Academy's profile picture

MalDev Academy

@MalDevAcademy20,032 subscribers

Providing specialized, module-based security training and resources designed for cyber security professionals

Shorts

Next week we are releasing a RunPE implementation which has been tested thoroughly against several EDRs. The demonstration video shows the implementation running Mimikatz and successfully evading Pe-seive.

Next week we are releasing a RunPE implementation which has been tested thoroughly against several EDRs. The demonstration video shows the implementation running Mimikatz and successfully evading Pe-seive.

48,870 views

We released a new public tool, 3LayersPersistence, that demonstrates 3 different persistence layers implemented in one executable. The implementation uses WMI event subscriptions, DLL sideloading, and COM hijacking in a single workflow, with the executable patching itself into proxy DLLs at runtime, allowing execution through multiple persistence paths.

We released a new public tool, 3LayersPersistence, that demonstrates 3 different persistence layers implemented in one executable. The implementation uses WMI event subscriptions, DLL sideloading, and COM hijacking in a single workflow, with the executable patching itself into proxy DLLs at runtime, allowing execution through multiple persistence paths.

11,890 views

The upcoming Malware Development course update will focus on persistence. The demo video below, part of our WMI persistence module, demonstrates achieving persistence when Microsoft Defender performs a signature update attempt.

The upcoming Malware Development course update will focus on persistence. The demo video below, part of our WMI persistence module, demonstrates achieving persistence when Microsoft Defender performs a signature update attempt.

12,539 views