Загрузка видео...

Не удалось загрузить видео

На главную

Introducing DarkWidow (Dropper/PostExploitation Toolkit): Capabilities: 1. Indirect Dynamic Syscall 2. SSN + Syscall address sorting via Modified TartarusGate approach (Other capabilities are in the comments...)

30,730 просмотров • 2 лет назад •via X (Twitter)

Комментарии: 10

Фото профиля Soumyani1
Soumyani12 лет назад

3. Remote Process Injection via APC Early Bird 4. Spawns a sacrificial Process as the target process 5. ACG(Arbitrary Code Guard)/BlockDll mitigation policy on spawned process 6. PPID spoofing 7. Cursed Nt Api resolving from TIB 8. Cursed Nt API hash If admin, kill Event Log svc!

Фото профиля Soumyani1
Soumyani12 лет назад

Shout out to these guys for directly/indirectly helping me out (Open Source Contribution :)): @SEKTOR7net @VirtualAllocEx @peterwintrsmith @D1rkMtr @Jean_Maes_1994 @0xBoku @_winterknife_

Фото профиля Daniel
Daniel2 лет назад

Congratulations, well done!

Фото профиля Soumyani1
Soumyani12 лет назад

Thanks a lot sir, ur blog really helping me :)

Фото профиля Bobby Cooke
Bobby Cooke2 лет назад

Looks cool, great work!

Фото профиля Soumyani1
Soumyani12 лет назад

Your project SPAWN really helped me to build this, previously when I was trying to grant both CIG and ACG mitigation policy to spawned process, I wasn't able to do that. After seeing your code and trying it out, it made much more sense to me. Thanks for that :)

Фото профиля spencer
spencer2 лет назад

Interesting. Adding this to my list of fun things to checkout. Nice work

Фото профиля Soumyani1
Soumyani12 лет назад

Thank u! Glad my project was able to slid into your "list of interest things" :)

Фото профиля urban.ntdll
urban.ntdll2 лет назад

Nice man…

Фото профиля Soumyani1
Soumyani12 лет назад

Thank u :)

Похожие видео