Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Introducing DarkWidow (Dropper/PostExploitation Toolkit): Capabilities: 1. Indirect Dynamic Syscall 2. SSN + Syscall address sorting via Modified TartarusGate approach (Other capabilities are in the comments...)

30,730 görüntüleme • 2 yıl önce •via X (Twitter)

10 Yorum

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

3. Remote Process Injection via APC Early Bird 4. Spawns a sacrificial Process as the target process 5. ACG(Arbitrary Code Guard)/BlockDll mitigation policy on spawned process 6. PPID spoofing 7. Cursed Nt Api resolving from TIB 8. Cursed Nt API hash If admin, kill Event Log svc!

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

Shout out to these guys for directly/indirectly helping me out (Open Source Contribution :)): @SEKTOR7net @VirtualAllocEx @peterwintrsmith @D1rkMtr @Jean_Maes_1994 @0xBoku @_winterknife_

Daniel profil fotoğrafı
Daniel2 yıl önce

Congratulations, well done!

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

Thanks a lot sir, ur blog really helping me :)

Bobby Cooke profil fotoğrafı
Bobby Cooke2 yıl önce

Looks cool, great work!

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

Your project SPAWN really helped me to build this, previously when I was trying to grant both CIG and ACG mitigation policy to spawned process, I wasn't able to do that. After seeing your code and trying it out, it made much more sense to me. Thanks for that :)

spencer profil fotoğrafı
spencer2 yıl önce

Interesting. Adding this to my list of fun things to checkout. Nice work

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

Thank u! Glad my project was able to slid into your "list of interest things" :)

urban.ntdll profil fotoğrafı
urban.ntdll2 yıl önce

Nice man…

Soumyani1 profil fotoğrafı
Soumyani12 yıl önce

Thank u :)

Benzer Videolar