Sign in

bohops

@bohops.bsky.social
128 followers 31 following 5 posts

Mostly on X

PostsRepliesMedia
Reposted by bohops
Hexacorn @hexacorn.bsky.social · 01/06/2025
mscoree.dll, RunDll32ShimW lolbin www.hexacorn.com/blog/2025/05...
073
bohops @bohops.bsky.social · 28/04/2025
Moving from pizza box servers and large tower PCs to mini and pico-style PCs has been absolutely amazing. A few NUCs and Pi s going along way.
000
bohops @bohops.bsky.social · 27/04/2025
When I was doing sysadmin work back in the day, I inherited a few systems like this. Legacy but rock solid. Worse part was no one knew what it was used for until we decided to disconnect the network cable one day.... 😀
110
bohops @bohops.bsky.social · 25/03/2025
Thank you, Casey! It definitely means a lot coming from you.
000
bohops @bohops.bsky.social · 25/03/2025
[Blog] This ended up being a great applied research project with my co-worker Dylan Tran on weaponizing a technique for fileless DCOM lateral movement based on the original work of James Forshaw. Defensive recommendations provided. - Blog: ibm.com/think/news/f... - PoC: github.com/xforcered/Fo...
ibm.com
Fileless lateral movement with trapped COM objects | IBM
New research from IBM X-Force Red has led to the development of a proof-of-concept fileless lateral movement technique by abusing trapped Component Object Model (COM) objects. Get the details.
01511
Reposted by bohops
Chris Thompson @retbandit.bsky.social · 19/03/2025
I am excited to announce the first conference dedicated to the offensive use of AI in security! Request an invite at offensiveaicon.com. Co-organized by RemoteThreat, Dreadnode, & DEVSEC.
173
Reposted by bohops
Clément Labro @itm4n.bsky.social · 19/02/2025
In this blog post, I explain how I was able to create a PowerShell console in C/C++, and disable all its security features (AMSI, logging, transcription, execution policy, CLM) in doing so. 💪 👉 blog.scrt.ch/2025/02/18/r...
Screenshot showing the execution of the proof-of-concept named PowerChell in comparison to a typical PowerShell prompt. In particular, it shows that PowerChell is able to bypass the Constrained Language Mode (CLM).
24319
Reposted by bohops
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
bohops @bohops.bsky.social · 15/01/2025
Apex Farms Red Team! I'm in.
010
Reposted by bohops
Brett Hawkins @h4wkst3r.bsky.social · 12/01/2025
You can find our @shmoocon.bsky.social presentation slides at the below GitHub repo. Thanks again to all that attended. Also, thank you to the conference organizers for putting on a great con and having us! #shmoocon github.com/h4wkst3r/Con...
github.com
11612