Offensive Twitter
19.1K subscribers
888 photos
47 videos
21 files
2.05K links
~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://t.iss.one/OffensiveTwitter/546
Download Telegram
😈 [ JasonFossen, Jason Fossen ]

How to host the PowerShell engine inside of Python and then run PowerShell code inside Python (and not spawn an external process):

https://t.co/kDal7LhP1e

#PowerShell #Python #SEC573 #SEC505 @MarkBaggett

πŸ”— https://devblogs.microsoft.com/powershell/hosting-powershell-in-a-python-script/

πŸ₯ [ tweet ]
😈 [ cfalta, Christoph Falta ]

I wrote something to compare the content of two volume shadow copies. Let's hope that's useful πŸ˜… #dfir #PowerShell
https://t.co/ip15QPFaTq

πŸ”— https://github.com/cfalta/vsctool

πŸ₯ [ tweet ]
😈 [ vinopaljiri, JiΕ™Γ­ Vinopal ]

Using #Powershell based on .NET >= 5 or .NET Core (so also latest Powershell Linux/Windows) you can easily natively manipulate with PE and do things like in the picture below (ML processing of .data section strings using #StringSifter) πŸ™ƒπŸ™ŒπŸ‘

πŸ₯ [ tweet ]
😈 [ last0x00, last ]

After a few weeks of development, I'm happy to share my new work: PersistenceSniper. It is a #Powershell module that allows #BlueTeams, #IncidentResponders and #Sysadmins to hunt persistences implanted in their Windows machines. Check it out!

https://t.co/oma0h8gFfF

πŸ”— https://github.com/last-byte/PersistenceSniper/

πŸ₯ [ tweet ]
😈 [ Gi7w0rm, Gi7w0rm ]

Just released a new #blogpost, where I analyze the initial stages of a #vbs / #powershell based #GuLoader / #CloudEye infection.
Shoutout to @malware_traffic for being the first to find this sample (which I noticed after analyzing it myself ^^).

1/2

πŸ”— https://gi7w0rm.medium.com/cloudeye-from-lnk-to-shellcode-4b5f1d6d877

πŸ₯ [ tweet ]
πŸ”₯2
😈 [ PrzemysΕ‚aw KΕ‚ys @PrzemyslawKlys ]

If you're into #ActiveDirectory, keep it clean from stale objects. CleanupMonster, my new #PowerShell module, can help you with that. I wrote a blog post about it to make it easier to implement.

It has fancy reporting and lots of customizations:

πŸ”— https://evotec.xyz/mastering-active-directory-hygiene-automating-stale-computer-cleanup-with-cleanupmonster/

πŸ₯ [ tweet ]
πŸ‘6