Загрузка видео...

Не удалось загрузить видео

На главную

🚨 I'm looking for a Job🚨 A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess. Project : =========== Looking for roles in User/Kernel mode Malware Dev, Evasion, Reverse Eng, Kernel Exploit Weaponization,...

17,113 просмотров • 1 год назад •via X (Twitter)

Комментарии: 7

Фото профиля Fawaz - بوجابر
Fawaz - بوجابر1 год назад

I was just mentioning your work to a couple of Moroccan friends a few hours ago Great work

Фото профиля Saad AHLA
Saad AHLA1 год назад

Thanks, I appreciate it, Fawaz 😁

Фото профиля jian liu
jian liu1 год назад

Please PM me, I have a lot of work to do.

Фото профиля jian liu
jian liu1 год назад

Hi bro

Фото профиля nemo
nemo1 год назад

kool and you will find your job boss

Фото профиля Moppel Mat
Moppel Mat1 год назад

No CrowdStrike kill?

Фото профиля Janus Pannonius
Janus Pannonius1 год назад

How you signed the driver?

Похожие видео

🚨 THREAT INTELLIGENCE ALERT 🚨 The tool 🇨🇳 KernelGhost820 is being actively sold on the underground market for US$ 2,500, complete with full source code. This is a professional-grade suite with an intuitive graphical interface and six advanced modules, specifically designed for EDR evasion and sophisticated ransomware operations with efficient lateral movement: • EDR Removal Engine: Automatically detects and terminates more than 40 security products (including CrowdStrike, SentinelOne, Microsoft Defender, Kaspersky, and others). Supports Kernel, UserMode, and NTDLL termination modes, kernel driver loading for protected processes, disabling Windows Defender, and blocking telemetry connections. • Ransomware Module: Dual encryption using AES256CBC + RSA2048, supporting over 70 file types (documents, images, databases, backups, etc.). Automatically deletes Volume Shadow Copies to prevent recovery, generates custom ransom notes with Bitcoin addresses and contact emails, and changes the desktop wallpaper. • Remote Operations & Mass Deployment: Connects to remote devices on the local network via WMI (requires username and password). Scans installed software on target hosts, performs process termination, and enables one-click full tool deployment. Includes full-network scanning for open SMB port 445 with real-time progress tracking. • Detailed Process Manager and full Operation Logger (exportable to TXT). This tool significantly lowers the technical barrier for advanced ransomware actors targeting corporate environments. Immediate monitoring recommendations: • Evaluate the resilience of your EDR/XDR controls against kernel-mode bypass techniques • Intensify monitoring of anomalous SMB (port 445) traffic and WMI connections • Strengthen network segmentation and the principle of least privilege Our team is actively tracking this tool and any emerging variants. #ThreatIntelligence #Ransomware #EDRBypass #CyberSecurity #InfoSec #CyberThreat

Clandestine

40,619 просмотров • 3 месяцев назад

⚠️ A defense evasion tool called ExEngine is being sold as a service, marketed as an AV/EDR killer that disables mainstream consumer security software including Windows Defender, Malwarebytes, Bitdefender, and Avast. The tool combines AV termination with a Ring-3 rootkit, UAC bypass, and decoy payload delivery to support stealthy initial access operations. ⠀ ‣ Threat Actor: ryewx1 ‣ Category: Defense Evasion Tool / Killer ‣ Offering: ExEngine AV/EDR Killer ‣ Industry: Malware Tooling ⠀ The seller claims ExEngine actively terminates security software rather than only obfuscating payloads, granting attackers a longer window of undetected operation. The tool supports Windows 10 and 11 builds and is sold per-build at $150 to $250. ⠀ Advertised capabilities: ⠀ ▪️ AV/EDR termination with primary and fallback techniques ▪️ UAC bypass with automatic privilege escalation ▪️ Ring-3 rootkit functionality to hide files, processes, registry keys, and network connections ▪️ Discord webhook logging for victim machine info and execution status ▪️ Secondary decoy payload (game/document/installer) to keep targets unaware ▪️ Persistence across reboots and logouts ▪️ Anti-VM and anti-debug detection with fake error message exit ▪️ Universal Windows 10/11 support, all payload types ⠀ Risk to defenders: ⠀ ▪️ Active termination of consumer AV products including Windows Defender means traditional endpoint protections cannot be relied on once ExEngine executes successfully ▪️ Decoy payload pattern is designed to delay user-driven incident reporting, lengthening attacker dwell time ▪️ Ring-3 rootkit hiding of files, processes, and network connections complicates incident response triage on compromised hosts ▪️ Discord webhook telemetry indicates the operator is targeting consumer and SMB victims at scale rather than running individual targeted campaigns ▪️ Sold per-build at low cost ($150 to $250), making it accessible to low-skill operators who can pair it with commodity stealers, RATs, or loaders

Dark Web Informer

23,210 просмотров • 2 месяцев назад

In one of our previous videos we demonstrated how to generate sideloading binaries by cloning the exports of an existing DLL to forward them - . However, using Microsoft DLLs and Microsoft-signed binaries is not the best OPsec, as it's easy for EDR vendors to create a detection rule for e.g. "version.dll" being loaded from a non-System32 directory. 🧐 We therefore recommend using third party signed executables that attempt to load their own DLL. This is much harder to track/map on the endpoint. If you know which functions are imported from your signed binary (see import table), you can also generate a sideloading DLL for persistence or initial access use cases. Bring your own third-party signed binary and voila - you're trusted! In this example, we sideload into java.exe, which is signed by Oracle. It attempts to load several DLLs - including jli.dll as shown in the video. #RustPack can easily create such DLLs with custom export functions - anti-debugging features, sandbox evasion, signature evasion and anti-emulation can be easily added. 🔥🔥 Userland hooks are bypassed by default options and you can enable custom AMSI/ETW bypasses for the process on top. If you want to use it for persistence, you can of course still clone the original DLL exports as we did in the previous video and forward them accordingly. 👍 Interested in buying RustPack? Contact us at info[at] ! #RedTeam #Pentest #OST #Maldev #Malware #Havoc

MSec Operations

10,686 просмотров • 1 год назад

New short course: Collaborative Writing and Coding with OpenAI Canvas! Explore new ways to write and code with OpenAI Canvas, a user-friendly interface that allows you to brainstorm, draft, and refine text and code in collaboration with ChatGPT. In the short course, created with OpenAI, and taught by , a research lead at OpenAI, you’ll learn to use Canvas to enhance your workflows. Canvas lets you go beyond simple chat interactions. It provides a side-by-side workspace where you and ChatGPT can edit and refine text or code collaboratively. This makes brainstorming, drafting, and iterating as you write feel more natural and effective. As the first major update to ChatGPT’s visual interface since its launch in 2022, Canvas gives a new, innovative approach to collaboration with AI. For instance, after writing the first version of your code, Canvas can review it and give suggestions for improvement. It can also help with debugging by adding logging, identifying problems to fix, and writing comments. In addition, you'll also learn what it takes to train the model for an interface like Canvas. In this video-only short course, you’ll: - Learn how to ask for in-line feedback and control the iteration of your work by directly editing selected areas of your text or code from the model’s output. - Learn how to access quick automation tools in a shortcut menu that allows you to modify your writing tone and length, enhance your code, and restore previous versions of your work. - Learn how to use Canvas as a research assistant tool with an example of asking the model to reason through the screenshot of a plot to write a research report, in which you can ask questions within the created report. - Ask the model to write Python code to replicate the graph seen on a screenshot image. - Go behind the scenes of how you can create a video game, such as Space Battleship, from scratch, edit it, and display it in one self-contained HTML file. - Get a real-world application example of creating a SQL database from the image of its architecture. - Understand the model training and design processes that power Canvas! Please sign up here:

Andrew Ng

128,180 просмотров • 1 год назад

The changes in the Algo and what Elon is truly trying to do - here is the full breakdown. A couple of Quick Points: - It all represents a really significant shift in what we’re about to see in our feed and the overall experience on X. - The shift from reply guy tactics to authenticity is where it’s all headed. - The value of a post will not be defined by engagement in its entirety but by the native value of the content. Current State: - Content visibility, including posts and replies, is currently unevenly prioritized, with manually written heuristics favoring recommendations to followers, benefitting large accounts but limiting the reach of smaller ones. - The "For You" algo heavily relies on these heuristics - impacting content reach and potentially hindering smaller accounts, regardless of content quality. Proposed Changes: - Algo defined value assignment to content will be driven by End-to-End Architecture based AI. - User-specific vectors, representing preferences, will guide content prioritization, providing a refreshed user experience within the feed that is inclusive and personalized. - The new approach will promote quality content across the entire user base, irrespective of account size. Additional Insights: - Elon emphasizes that AI will play a pivotal role in content importance assignment, suggesting a departure from the current manually-driven processes. - The algo will differentiate between content from accounts users follow (non-AI recommended) and those they don't (AI recommended), which should significantly improve the diversity of the content we’re exposed to. Implications: The proposed changes signify a fundamental transformation in how content is presented and recommended, with a move towards a more democratic and AI-driven system. Smaller accounts may benefit from increased visibility, creating a more level playing field based on content quality rather than follower count. Theories: - The mention of AI-differentiated recommendations for followed and non-followed content suggests a strategic effort to broaden user exposure to diverse content. - The shift towards an AI-powered recommendation system indicates a commitment to enhancing user experience by tailoring content suggestions based on individual preferences. What we’re looking at is a change that finally addresses the FOMO dynamic between accounts with reach and truly compelling content. It will be a major chance for new accounts, small accounts, and anyone really - to advance into the greater ecosphere they were left out of before. Goodbye, reply guy. Hello, value adding content. These conclusions are based on the recent interview of Elon Musk by Lex Fridman.

Adrian Dittmann

313,553 просмотров • 2 лет назад

🚨APPLE SPENT 5 YEARS AND BILLIONS OF DOLLARS BUILDING THE MOST ADVANCED SECURITY SYSTEM IN CONSUMER HISTORY.. AN AI BROKE IT IN 5 DAYS.. Here’s what just happened.. Apple built something called Memory Integrity Enforcement for its new M5 chips.. It’s a hardware-level security system that attaches secret cryptographic tags to every piece of memory.. If a hacker tries to access memory they shouldn’t.. The chip blocks it instantly.. Every known exploit chain against iOS and macOS was rendered obsolete overnight.. Apple said so themselves.. Then a small team at a cybersecurity firm called Calif used Anthropic’s unreleased Claude Mythos Preview to find vulnerabilities in the macOS kernel.. The AI found the bugs almost instantly.. Because once it learned the pattern of a specific type of flaw.. It could recognize every other flaw in that same class across the entire codebase.. What used to take elite security teams months.. The AI did in hours.. Within 5 days.. The team had a fully working exploit that escalated a basic user account to full root access on an M5 Mac running the latest macOS.. With MIE fully enabled.. The billion-dollar hardware defense running at full strength.. The trick.. They didn’t fight the hardware.. They went around it.. MIE is designed to catch memory corruption.. Hackers trying to overwrite pointers or inject code.. The team used a “data-only” approach instead.. They manipulated legitimate data structures the hardware was never designed to monitor.. Like changing an internal flag from “standard user” to “admin”.. The chip saw a perfectly normal operation.. The operating system obeyed.. And the attacker had total control.. The hardware thought everything was fine.. Because technically it was.. The exploit never triggered a single tag mismatch.. They walked into Apple Park and hand-delivered a 55-page report.. Apple patched it in macOS 26.5.. And for the first time ever.. Apple’s official security advisory credited the vulnerability discovery to “Calif dot io in collaboration with Claude and Anthropic Research”.. An AI is now credited in Apple’s CVE patches.. But here’s what makes this story truly terrifying.. Before MIE existed.. An exploit kit called DarkSword was hitting iPhones with zero-click attacks.. Six vulnerabilities chained together.. Total device control just from visiting a webpage.. Deployed by Russian espionage groups, Turkish surveillance vendors, and actors in Saudi Arabia.. Then it got leaked on GitHub.. Nation-state capabilities.. Free for anyone.. MIE was supposed to make all of that impossible.. And an AI found a way around it in 5 days.. The previous model.. Claude Opus 4.6.. Found 22 security bugs in the Firefox codebase.. Claude Mythos Preview found 271 in the same environment.. A tenfold increase.. Linux kernel CVEs jumped from 300 per year to over 5,500.. Largely driven by AI-powered vulnerability research.. The IMF designated Claude Mythos as a systemic financial stability risk.. Because if an AI finds a flaw in software used by every major bank simultaneously.. It could trigger a cascading financial crisis.. Anthropic knew this was coming.. That’s why they didn’t release the model publicly.. Instead they launched Project Glasswing.. Giving defensive access to AWS, Apple, Google, Microsoft, Nvidia, CrowdStrike, JPMorgan, and others.. $100 million in usage credits.. So defenders can scan their own systems before attackers get this capability.. The Pentagon blacklisted Anthropic over autonomous weapons.. Then quietly started using Mythos to harden government systems anyway.. The cybersecurity arms race just changed permanently.. Hardware can’t save you.. Software can’t save you.. The only defense against an AI that finds vulnerabilities is another AI that finds them first.. Five years and billions of dollars.. Five days and one AI.

Evan Luthra

91,085 просмотров • 2 месяцев назад

I Built a website with a front end & a backend by prompting Claude and either... 1. Pasting the code into replit (or) 2. Following its instructions on Firebase I filmed the whole thing.... But, this is by no means a tutorial lol. so I recommend skipping around. This can be best described as a worthwhile struggle. Theres 3 hours of cut footage of me getting annoyed, but I was able to create something that will serve as a home page for my business, where I can house the AI apps I create going forward. And by the end, you'll see that I actually know my way around the different parts of Firebase, and my confidence level working with code has gone up 1,000,000%. I'm beginning to know what each file does, and what context Claude needs to be successful in creating what I want to build. Ready for my next project. See you later this week, i'm tired lol... (video was harder than the site....) TimeStamps ------------------------------------------------------ 00:00 - Introduction and project overview 07:21 - Using Claude Artifact 21:00 - Setting up Firebase backend and user authentication 30:00 - Adding Firebase Collections (database) 39:10 - WE DID IT! 45:20 - Implementing lesson editing functionality 54:00 - Separating code into manageable chunks for easier editing 56:00 - Access control for signed-in users 01:01:32 - Connecting the custom domain (create dot inc) 01:02:41 - Showcasing additional features (user count, music feature) 01:05:26 - Discussing future plans and improvements ------------------------------------------------------

Riley Brown

210,639 просмотров • 2 лет назад

🚨🚨 CALLING FLORIDA REPUBLICAN VOTERS 🚨🚨 RPOF Chairman, Evan Power, calls out governor DeSantis and says that his call for debates is creating a sideshow. See the video of Evan Power below. Calling for transparency and debates is not a sideshow. However, the process created by the RPOF and the refusal to allow a debate of all candidates is a clear attempt to install Byron Donalds without any regard for Republican voters. Many things don't add up. For example, below I also included two screenshots of comments made by Kristina Heuser. She admits that she is on the Executive Board of the RPOF and that the criteria to qualify for the debate was created last year and that all candidates were informed. She doesn't say that the members of the RPOF executive committee voted for it or that they were involved in its creation. She isn't questioning the decision either because she is more than happy with the outcome. Why wouldn't she be? She has publicly endorsed Byron Donalds, the only candidate who meets the criteria for the debate. Below you can also find a screenshot of a post written by Florida Representative, Michelle Salzman. She said that she is also a member of the RPOF Executive Committee and that she doesn't agree with the decision made regarding the debate criteria. She also makes it clear that it was a UNILATERAL decision. In other words, she wasn't involved in the process. All candidates, except Byron Donalds, have stated that they were not informed of the criteria prior to the RPOF making it public last week. These are the questions ALL Republicans should be asking of Evan Power and the RPOF. 👇 👇 1) When did the RPOF create the criteria for the debates? We demand specific dates. 2) Who were the people involved in creating the criteria? We demand specific names. 3) When did they inform all the campaigns in writing? If they did, we demand to see that letter, text, email, etc. 4) If the criteria was created last year as one executive committee member, Kristina Heuser, has stated, then why did the RPOF state on their website on January 7, 2026 that the criteria for debates would be published several weeks after that, but it wasn't done until 5 months later? WE MUST DEMAND FROM THE RPOF. Every member on the Executive Committee of the RPOF was a elected by Republican voters as a State Committeeman or State Committeewoman to represent Republicans in their county at the state party and Evan Power was voted in as Chair by them!

Dr. Maria Peiro 🇺🇸 🐊

12,241 просмотров • 1 месяц назад

🚨GREATER ISRAEL PLAN: ‘Israel wants to be surrounded by failed, fragmenting, or co-opted states. Its goal in Iran is STATE COLLAPSE, NOT regime change.’ —Former Israeli Peace Negotiator Daniel Levy ‘What I’m suggesting is that the notion of a Greater Israel dominion, a project of domination in the region, is not just about territory. It’s about how far Israel can extend its hard power hegemony. And to do that, it wants to create a situation where it is surrounded by states that are either collapsed, in the process of fragmenting and dismantling, and therefore cannot prevent any challenge to that hard power Greater Israel project… Or states which find themselves easily co-opted by Israel because of vulnerabilities and dependencies that are brought into play, often actively by Israel. What Israel is trying to do is not some dream of regime change in Iran. It doesn’t really believe that. It’s going for regime and state collapse, chaos that then spills over. So that deals with Iran. Saudi Arabia being attacked in the war on Iran was by design as far as the Israelis are concerned. Because part of the goal here is to weaken the Gulf states so that they look around and they say, ‘America couldn’t deliver for us. We may not all like it, but there is a major regional power here and we are going to have to get on board with its project.’ Israel has talked openly about not only being a regional superpower, but Netanyahu has said becoming a global superpower. It’s talked about corridors for transporting Gulf oil to market that would run through to Israel’s Mediterranean ports. So it is trying to create Gulf dependencies on Israel. I’m not saying it will succeed.’ Watch the full interview in the quoted post below👇

Going Underground

45,984 просмотров • 3 месяцев назад

Goodnight, 𝕏..·˚ ༘ ☾ ⋆。˚ ☄︎ Here's a fun project you can start with Grok 4. Use Grok-Code-Fast-1 to build your own OS. Below is a prompt that you can give to Grok-Code, and it will set up a solid foundation for a Linux-based Operating system that you can build from the ground up with Grok4. >>> Grok 4 Prompt You are a fully capable AI developer agent with expert-level experience as an embedded Linux systems engineer. You have deep expertise in using automated build systems like Buildroot and Yocto to create custom operating systems from source. You have access to a sandboxed Linux shell environment that allows you to write, execute, and debug code. Your mission is to generate a complete project skeleton for a minimal, custom Linux OS, and then you will execute the build scripts yourself to verify their correctness, automatically fixing any issues that arise. This is NOT a request to follow the Linux From Scratch (LFS) book. You will use the Buildroot build system to automate the entire process. You will follow a two-phase process: Phase 1: Generation and Phase 2: Execution and Iterative Debugging. ------------------------------------------------------------- Phase 1: Code and Script Generation First, you will generate all the necessary files for the project skeleton. All generated shell scripts must be robust and path-aware, executing correctly from any directory [Previous conversation]. Detailed Implementation Steps (using Context-Aware Decomposition): 1. Generate the Project Directory Structure via setup. sh Create a setup. sh script that establishes the following directory structure: • buildroot/ - Where the Buildroot source code will be cloned. • configs/ - To store our custom Buildroot configuration (defconfig). • board/ - For custom board support, including a readme.txt explaining its purpose for filesystem overlays. • output/ - Where all build artifacts will be placed. • scripts/ - A home for our build. sh and test. sh scripts. Crucially, this setup. sh script (and all others) must begin with a preamble to define the project's root directory, making all subsequent paths absolute and robust: #!/bin/bash # Preamble to ensure path robustness and stop on error set -e PROJECT_ROOT="$(cd "$(dirname "${BASH_SOURCE}")" && pwd)" The script must then clone the latest stable branch of Buildroot into $ PROJECT_ROOT/buildroot/. 2. Create the Minimal and Correct Buildroot defconfig Create a file named configs/tiny_linux_defconfig. This configuration must be the absolute bare minimum required to boot to a shell and must contain the exact configuration options listed below to avoid ambiguity and known errors: • Target Architecture: x86_64. • Toolchain: Use the default Buildroot toolchain. • Init System: Use BusyBox init. • System Utilities (BusyBox): ◦ To ensure BusyBox is statically linked without errors, you must include the following line directly in the defconfig file: BR2_PACKAGE_BUSYBOX_STATIC_LINK=y [Previous conversation, 298, 753]. ◦ To prevent the ROJECT_ROOT error, explicitly do NOT use a configuration fragment for BusyBox. Do not generate any lines containing BR2_BUSYBOX_CONFIG_FRAGMENT_FILES [Previous conversation]. • Kernel: ◦ Build the latest stable Linux kernel. ◦ Use tinyconfig as a base. ◦ Ensure the following options are explicitly enabled (=y) to make it bootable in QEMU: CONFIG_64BIT=y, CONFIG_DEVTMPFS=y, CONFIG_DEVTMPFS_MOUNT=y, CONFIG_BINFMT_ELF=y, CONFIG_BLK_DEV_INITRD=y (for initramfs support), CONFIG_TTY=y, CONFIG_PRINTK=y, CONFIG_DRM_FBDEV_EMULATION=y (for UEFI framebuffer console). • Filesystem Image: Configure it to produce a compressed cpio initial ramdisk (initramfs) image. • Bootloader: Do not include GRUB or other bootloaders. We will boot the kernel directly with QEMU. 3. Generate the scripts/build.sh and scripts/test.sh Scripts Generate path-aware build and test scripts, placing them in the scripts/ directory. • scripts/build.sh: This script must use absolute paths derived from a preamble. It must use make -C "$PROJECT_ROOT/buildroot" O="$PROJECT_ROOT/output" ... for a clean, out-of-tree build. It must include the -j$(nproc) flag to maximize build speed on multi-core systems [111, 967, Previous conversation]. • scripts/test.sh: This script must also be path-aware and launch QEMU using absolute paths to the kernel (bzImage) and initramfs (rootfs.cpio.gz) images. 4. Generate a Detailed README. md File Generate a comprehensive README. md file. It must explain prerequisites, "How to Customize Your Linux System" first, and finally, the "Quick Start" instructions for user clarity [Previous conversation]. ------------------------------------------------------------- Phase 2: Execution and Iterative Debugging Now, you will use your sandboxed Linux shell to verify and validate the scripts you just generated. This is a critical self-correction step based on the Recursive Criticism and Improvement (RCI) pattern. You will perform a full build cycle. 1. Execute setup. sh: • Run the setup. sh script you generated. • Capture the standard output and standard error. • If the script fails: Analyze the error, diagnose the root cause, generate the corrected setup. sh code, and then execute the corrected script to confirm it succeeds. 2. Execute build. sh: • After setup. sh completes successfully, run the scripts/build.sh script. This will trigger a full compilation of the Linux system. • Capture all output. • If the build fails: ◦ Analyze: Analyze the compiler error output. ◦ Diagnose: Identify the root cause (e.g., missing dependencies, incorrect configuration flags, pathing errors). ◦ Correct: Based on your analysis, identify which file is responsible for the failure (e.g., configs/tiny_linux_defconfig, scripts/build.sh) and generate the corrected code for that file. ◦ Repeat: Repeat the execution of scripts/build.sh until the build completes successfully without any errors. 3. Final Output: Once you have successfully executed both setup. sh and scripts/build.sh, you will present your final output. • First, provide the final, validated versions of all generated files (setup. sh, configs/tiny_linux_defconfig, scripts/build.sh, scripts/test.sh, and README. md) in separate, clearly labeled markdown code blocks. • Second, follow the code with a brief execution log. This log should summarize your actions, including any errors you encountered and fixed during the iterative debugging phase, demonstrating the self-correction process.

Tetsuo

2,840,991 просмотров • 9 месяцев назад