Aggregator
OdinLdr: Cobaltstrike Reflective Loader with Synthetic Stackframe
OdinLdr Cobaltstrike UDRL for beacon and post-ex tools. Use NtApi call with synthetic stackframe to confuse EDR based on stackframe detection. Beacon Use BeaconUserData structure to give memory information to beacon and allocate memory...
The post OdinLdr: Cobaltstrike Reflective Loader with Synthetic Stackframe appeared first on Penetration Testing Tools.
原生新链-SPring AOP 原生链挖掘思路分析
突破 .NET 身份认证,上传定制化 web.config 实现RCE
.NET内网实战: 通过 sdclt.exe 绕过 UAC 实现提权
实战上传 DLL 型 WebShell,一文详解 .NET 程序集 VS C++ 动态链接库的区别
pcfg_cracker: perform research into how humans generate passwords
pcfg_cracker This project uses machine learning to identify password creation habits of users. A PCFG model is generated by training on a list of disclosed plaintext/cracked passwords. In the context of this project, the...
The post pcfg_cracker: perform research into how humans generate passwords appeared first on Penetration Testing Tools.
sherloq: open-source digital image forensic toolset
Introduction “Forensic Image Analysis is the application of image science and domain expertise to interpret the content of an image and/or the image itself in legal matters. Major subdisciplines of Forensic Image Analysis with...
The post sherloq: open-source digital image forensic toolset appeared first on Penetration Testing Tools.
Weekly Report: Ivanti Connect Secureなどにおけるスタックベースのバッファーオーバーフローの脆弱性
Lockbit
我用NodeJS+electron自研了个C2和木马并绕过了360+火绒内存扫描(附源码)
从0-1详解剖析ret2dlresolve
Lynx
Apache mina反序列化漏洞
SwampCTF Re WP
Daily Dose of Dark Web Informer - 8th of April 2025
Lawsuit: Hospital Pharmacist Spied on Coworkers for a Decade
An academic medical center is facing a class action lawsuit alleging one of its pharmacists installed keylogging software on 400 computers over a decade to spy on the personal lives and intimate moments of coworkers. The pharmacist is also facing a criminal investigation, the hospital said.
Russian APT Hacker Observed Deploying Unusual RDP Tactics
A Russian nation state threat actor exploited "lesser known" features of Microsoft Windows remote desktop protocol to target European organizations for espionage. Hackers using RDP to deploy a malicious application and access data from victims.
US Risks Losing 'AI Cold War' as China Surges Ahead
The United States risks losing the so-called "AI Cold War" against China unless it abandons traditional containment strategies and adapts to Beijing's advances, panelists told lawmakers Tuesday. "I'm as stunned as all of you about just how fast China has caught up," said Adam Thierer.
Tailscale Raises $160M to Scale AI and Enterprise Use
Tailscale has landed $160 million in Series C funding to scale its platform and meet growing demand from AI and enterprise firms. The networking company will invest in engineering to support multi-cloud and identity-based networking features.