Avatar
CrowdCyber
36f403b6512d7e69bb7b89442ce43ffa63cdf6ead2641d7935b239e2ec3557ad
Revolutionizing and Democratizing Cybersecurity

Modern Asian APT groups’ tactics, techniques and procedures (TTPs) https://securelist.com/modern-asia-apt-groups-ttp/111009/

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime https://github.com/TheD1rkMtr/UnhookingPatch

Persistent Threat: New Exploit Puts Thousands of GitHub Repositories and Millions of Users at Risk https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/

CacheWarp is a new software fault attack on AMD SEV-ES and SEV-SNP. It allows attackers to hijack control flow, break into encrypted VMs, and perform privilege escalation inside the VM. https://cachewarpattack.com/

Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks https://github.com/Cr4sh/SmmBackdoorNg

EDRaser - Tool For Remotely Deleting Access Logs, Windows Event Logs, Databases, And Other Files https://www.kitploit.com/2023/09/edraser-tool-for-remotely-deleting.html?m=1

Attacking an EDR - Part 1 - For some fun and a fair bit of profit https://riccardoancarani.github.io/2023-08-03-attacking-an-edr-part-1/

Reptar: an Intel Ice Lake CPU vulnerability, by Tavis Ormandy https://lock.cmpxchg8b.com/reptar.html