-
Practical Security Analytics
- https://practicalsecurityanalytics.com/
- @prac_sec
Stars
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
Windows Privilege Escalation from User to Domain Admin.
A ultra-lightweight embedded scripting language optimized for microcontrollers.
A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.
Collection of UAC Bypass Techniques Weaponized as BOFs
CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback
Threadless Injection injects a trampoline at the start of the target function instead of stomping it with the entire payload. This trampoline will redirect the execution to the main shellcode injec…