Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Introducing DarkWidow (Dropper/PostExploitation Toolkit): Capabilities: 1. Indirect Dynamic Syscall 2. SSN + Syscall address sorting via Modified TartarusGate approach (Other capabilities are in the comments...)

30,730 Aufrufe • vor 2 Jahren •via X (Twitter)

10 Kommentare

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

3. Remote Process Injection via APC Early Bird 4. Spawns a sacrificial Process as the target process 5. ACG(Arbitrary Code Guard)/BlockDll mitigation policy on spawned process 6. PPID spoofing 7. Cursed Nt Api resolving from TIB 8. Cursed Nt API hash If admin, kill Event Log svc!

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

Shout out to these guys for directly/indirectly helping me out (Open Source Contribution :)): @SEKTOR7net @VirtualAllocEx @peterwintrsmith @D1rkMtr @Jean_Maes_1994 @0xBoku @_winterknife_

Profilbild von Daniel
Danielvor 2 Jahren

Congratulations, well done!

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

Thanks a lot sir, ur blog really helping me :)

Profilbild von Bobby Cooke
Bobby Cookevor 2 Jahren

Looks cool, great work!

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

Your project SPAWN really helped me to build this, previously when I was trying to grant both CIG and ACG mitigation policy to spawned process, I wasn't able to do that. After seeing your code and trying it out, it made much more sense to me. Thanks for that :)

Profilbild von spencer
spencervor 2 Jahren

Interesting. Adding this to my list of fun things to checkout. Nice work

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

Thank u! Glad my project was able to slid into your "list of interest things" :)

Profilbild von urban.ntdll
urban.ntdllvor 2 Jahren

Nice man…

Profilbild von Soumyani1
Soumyani1vor 2 Jahren

Thank u :)

Ähnliche Videos