[Zrok] - CobaltStrike Over WAN Connection
· β˜• 1 min read · 🐱 thik
αžαž—αŸ’αž‡αžΆαž”αŸ‹αž“αž·αž„αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαž€αŸ’αž“αž»αž„ CobaltStrike αž–αžΈαž…αŸ†αž„αžΆαž™

MSFvenom:- Raw2Shellcode and Remove Garbage
· β˜• 1 min read · 🐱 thik
αž™αž›αŸ‹αžŠαžΉαž„αž’αŸ†αž–αžΈαž€αžΆαžšαž”αŸ†αž”αŸ’αž›αŸ‚αž„αž―αž€αžŸαžΆαžš Raw αž‘αŸ…αž‡αžΆ Shellcode αž“αž·αž„αžŠαž€αž…αŸ†αž“αž½αž“αž˜αž·αž“αž”αžΆαž“αž€αžΆαžšαž…αŸ„αž›

Best Way To Obfuscate a Batch File
· β˜• 1 min read · 🐱 thik
αž™αž›αŸ‹αžŠαžΉαž„αž’αŸ†αž–αžΈαž€αžΆαžšαž’αŸ’αžœαžΎ Obfuscate αž‘αŸ…αž›αžΎαž―αž€αžŸαžΆαžš Batch

Hijacking Digital Signatures
· β˜• 1 min read · 🐱 thik
αžαŸ’αž›αžΈαžƒαŸ’αž›αžΉαž˜αž’αŸ†αž–αžΈαžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžšαž›αž½αž…αž™αž€ Digital Signatures

DLL Hijacking Attack 0x01
· β˜• 1 min read · 🐱 thik
αž™αž›αŸ‹αžŠαžΉαž„αž’αŸ†αž–αžΈαž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž”αŸ‚αž” DLL Hijacking

Malicious Alternate Data Streams In Windows
· β˜• 1 min read · 🐱 thik
αž›αžΆαž€αŸ‹αž‘αž·αž“αŸ’αž“αž“αŸαž™αžŸαŸ†αž„αžΆαžαŸ‹αž€αŸ’αž“αž»αž„αžœαžΈαž“αžŠαžΌ Data Steams

Encrypting Shellcode with XOR In C
· β˜• 1 min read · 🐱 thik
αž€αžΌαžŠαž“αžΈαž™αž€αž˜αŸ’αž˜ Shellcode αž‡αžΆαž˜αž½αž™ XOR αž€αŸ’αž“αž»αž„αž—αžΆαžŸαžΆαžš C

Evading AV/EDR with Curl Command
· β˜• 2 min read · 🐱 thik
αžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžš Evading AV/EDR αžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ Curl

Evading AV/EDR with Junk Bytes
· β˜• 1 min read · 🐱 thik
αžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžš Evading AV/EDR αžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ Junk Bytes

Process Injection - Bypass AV/EDR with XOR - 0x01
· β˜• 3 min read · 🐱 thik
αž…αžΆαž€αŸ‹αž”αž‰αŸ’αž‡αžΌαž› Shellcode αž“αž·αž„ Bypass AV/EDR αžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ XOR

Process Injection without Write/Execute Permission
· β˜• 1 min read · 🐱 thik
αž…αžΆαž€αŸ‹αž”αž‰αŸ’αž‡αžΌαž› Shellcode αž€αŸ’αž“αž»αž„ Process αžŠαŸ„αž™αž‚αŸ’αž˜αžΆαž“ Write/Exec Allocation

Process Injection - Self Injection Method
· β˜• 1 min read · 🐱 thik
αž…αžΆαž€αŸ‹αž”αž‰αŸ’αž‡αžΌαž› Shellcode αž€αŸ’αž“αž»αž„ Process αžŠαŸ„αž™αž”αŸ’αžšαžΎαžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžš Self Injection

CobaltStrike Over WAN Connection
· β˜• 1 min read · 🐱 thik
αžαž—αŸ’αž‡αžΆαž”αŸ‹αž“αž·αž„αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαž€αŸ’αž“αž»αž„ CobaltStrike αž–αžΈαž…αŸ†αž„αžΆαž™