Alaid TechThread
548 subscribers
6 photos
1 video
80 files
1.3K links
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
Download Telegram
Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting technique. Also, launchers are totally anti-copy and naturally broken when got submitted.

https://github.com/aaaddress1/Skrull
Detection Lab

Collection of Packer & Vagrant scripts that quickly bring a Windows AD online, complete with a collection of endpoint security tooling & logging best practices

https://medium.com/@clong/introducing-detection-lab-61db34bed6ae
poc_2021.pdf
3.2 MB
Pwning the Windows 10 Kernel with NFTS and WNF