Data breach revealed,
Malware lurks, silent, stealthy -
OSINT tracks the thread.
URLs I post may contain malware – be careful and check yourself before running anything.
Posts
A post about how to use Page Guard Exceptions to bypass AMSI
When Windows Defender realizes that a malicious file has a cloud tag it rewrites the file to it's original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges.
It is possible as a low privileged user to parse the Windows event logs for any ASR exclusion
A new ClickFix variant dubbed "CrashFix" that intentionally crashes the browser then baits users into running malicious commands
https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
#infosec #cybersecurity #threatintel #phishing #malware #redteam