Sign in

Antonio Cocomazzi

@splintercode.bsky.social
374 followers 275 following 12 posts

offensive security - windows internals - reverse engineering | X: x.com/splinter_code | Mastodon: infosec.exchange/@splinter_code | GitHub: github.com/antonioCoco | Blog: splintercod3.blogspot.com

PostsRepliesMedia
Reposted by Antonio Cocomazzi
SentinelOne @sentinelone.com · 03/02/2025
🚨 Alert: New macOS Malware Variants, FlexibleFerret, Undetected by Apple’s XProtect 🚨 @sentinellabs.bsky.social researchers @philofishal.bsky.social and @hegel.bsky.social have uncovered new variants, which slip past Apple's XProtect, of the DPRK-linked macOS malware, Ferret.
s1.ai
macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed
DPRK 'Contagious Interview' campaign continues to target Mac users with new variants of FERRET malware and Github devs with repo spam.
285
Reposted by Antonio Cocomazzi
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Antonio Cocomazzi @splintercode.bsky.social · 29/01/2025
Very interesting post by Microsoft about the internals of the new Admin Protection feature It seems they have patched my SSPI UAC bypass based on NTLM as well as the Kerberos UAC bypass in which both were able to bypass AP as well More details here 👇 techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Evolving the Windows User Model – Introducing Administrator Protection | Microsoft Community Hub
Previously, in part one, we outlined the history of the multi-user model in Windows, how Microsoft introduced features to secure it, and in what ways we got...
162
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 09/01/2025
Had some fun reviving an old vulnerable driver, read all about it here: decoder.cloud/2025/01/09/t... 🤠
decoder.cloud
The (Almost) Forgotten Vulnerable Driver
Vulnerable Windows drivers remain one of the most exploited methods attackers use to gain access to the Windows kernel. The list of known vulnerable drivers seems almost endless, with some not even…
053
Reposted by Antonio Cocomazzi
Nathan McNulty @nathanmcnulty.com · 19/12/2024
Thanks to a recent post from @ericlawrence.com on Defender and Dev Drive, I was reminded of this amazing research series by @n4r1B n4r1b.com/posts/2020/0... I only comprehend ~30% if I'm lucky, but that's a good 10% more than last time I read it 🤣 Still, it's definitely worth reading ;)
n4r1b.com
Dissecting the Windows Defender Driver - WdFilter (Part 1)
In this series of posts I'll be explaining how the Windows Defender main Driver works, in this first post we will look into the initialization and the Process creation notifications among other things
0133
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 13/12/2024
Working in it .... 😇 www.youtube.com/watch?v=fUqC...
053
Antonio Cocomazzi @splintercode.bsky.social · 13/12/2024
@decoder-it.bsky.social and i noticed that it's no more possible to call NtLoadDriver pointing to an unprivileged regkey such as \REGISTRY\USER Even if you have the SeLoadPrivilege you would still require the Admin group to write the required regkey. Some more technical details below 👇
133
Reposted by Antonio Cocomazzi
SentinelLABS @sentinellabs.bsky.social · 12/12/2024
🔮 What does the future hold? Surprises 🎲, certainly, but some of the forces that will shape #2025 can already be discerned in the shadows of 2024. The @sentinellabs.bsky.social team takes a look at what might be coming over the horizon for #cybersecurity this coming year.
063
Reposted by Antonio Cocomazzi
RastaMouse @rastamouse.me · 08/12/2024
[BLOG] Today's post is all about Cobalt Strike's Postex Kit. rastamouse.me/cobalt-strik...
rastamouse.me
Cobalt Strike Postex Kit
The CS 4.10 update saw the introduction of the Postex Kit. This was a bit overshadowed by BeaconGate, which was also added in 4.10 (I wrote about this in my last post). The intention of this post is t...
0142
Reposted by Antonio Cocomazzi
RastaMouse @rastamouse.me · 30/11/2024
[BLOG] This post summarises how to tie Cobalt Strike's UDRL, SleepMask, and BeaconGate together for your syscall and call stack spoofing needs. rastamouse.me/udrl-sleepma...
rastamouse.me
UDRL, SleepMask, and BeaconGate
I've been looking into Cobalt Strike's UDRL, SleepMask, and BeaconGate features over the last couple of days. It took me some time to understand the relationship between these capabilities, so the aim...
03215
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 29/11/2024
Relaying DCOM has always intrigued me, so I decided to dive in. Started with a MiTM attack using a fake DNS entry, targeting certificate requests to an ADCS server and relaying to SMB.
183
Reposted by Antonio Cocomazzi
Hexacorn @hexacorn.bsky.social · 28/11/2024
Windows.Storage . lol www.hexacorn.com/blog/2024/11...
0199
Reposted by Antonio Cocomazzi
SentinelOne @sentinelone.com · 26/11/2024
💡Dr. Cristina Cifuentes, the Mother of Decompilation, reflects in her #LABScon2024 keynote on three decades of innovation in reverse engineering. 📺 Watch the full video: s1.ai/LC24-CC
13616
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 25/11/2024
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
36343
Reposted by Antonio Cocomazzi
BleepingComputer @bleepingcomputer.com · 23/11/2024
A new malicious campaign is using a legitimate but old and vulnerable Avast Anti-Rootkit driver to evade detection and take control of the target system by disabling security components. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers abuse Avast anti-rootkit driver to disable defenses
A new malicious campaign is using a legitimate but old and vulnerable Avast Anti-Rootkit driver to evade detection and take control of the target system by disabling security components.
0147
Reposted by Antonio Cocomazzi
Tom Hegel @hegel.bsky.social · 21/11/2024
🚨 New Research Drop: 🇰🇵 DPRK IT Workers | A Network of Active Front Companies and Their Links to China Summary: ⚪ Newly Disrupted Front Companies by USG ⚪ Impersonating US based software and tech orgs ⚪ Links to still-active front orgs, CN association Report: www.sentinelone.com/labs/dprk-it...
sentinelone.com
DPRK IT Workers | A Network of Active Front Companies and Their Links to China
SentinelLabs has identified multiple deceptive websites linked to businesses in China fronting for North Korea's fake IT workers scheme.
13723
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 20/11/2024
Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)
13614
Reposted by Antonio Cocomazzi
Dirk-jan @dirkjanm.io · 20/11/2024
Awesome new addition to krbrelayx by Hugow from Synacktiv: www.synacktiv.com/publications...
synacktiv.com
Relaying Kerberos over SMB using krbrelayx
02914
Reposted by Antonio Cocomazzi
Justin Elze @handle.invalid · 19/11/2024
TrustedSec Tech Brief 00:30 - NTLM Hash Disclosure Zero-Day 01:45 - Task Scheduler Vulnerability 02:30 - Exchange Server Issues 03:15 - AD Certificate Services Flaw 04:00 - Vulnerability Breakdown 04:45 - Palo Alto Zero-Day 05:30 - FortiGate VPN Update www.youtube.com/watch?v=3mSD...
youtube.com
TrustedSec Tech Brief - November 2024
YouTube video by TrustedSec
36121
Reposted by Antonio Cocomazzi
Phil Stokes ⫍🐠⫎ @philofishal.bsky.social · 18/11/2024
What we saw with Hidden Risk (s1.ai/BNThief), we’ll see plenty more of in 2025: threat actors exploring all the old methods of #macOS persistence because the lazy LaunchAgents way is now too noisy thanks to changes Apple made in Ventura.(1/2)
184
Antonio Cocomazzi @splintercode.bsky.social · 18/11/2024
www.justice.gov/opa/pr/phobo...
justice.gov
Phobos Ransomware Administrator Extradited from South Korea to Face Cybercrime Charges
The Justice Department unsealed criminal charges today against Evgenii Ptitsyn, 42, a Russian national, for allegedly administering the sale, distribution, and operation of Phobos ransomware. Ptitsyn ...
000
Reposted by Antonio Cocomazzi
Andrea P @decoder-it.bsky.social · 17/11/2024
Working on my "new" Kerberos Relay & PortForwarder tool designed for managing also MITM attacks 😇
1111
Reposted by Antonio Cocomazzi
Nathan McNulty @nathanmcnulty.com · 17/11/2024
Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this... I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working Apparently this is built into Chrome/Edge! So cool :) edge://net-export/
1518645
Reposted by Antonio Cocomazzi
Ollie Whitehouse @ollieatnowhere.bsky.social · 16/11/2024
Weekly summary is out... ctoatncsc.substack.com/p/cto-at-ncs...
ctoatncsc.substack.com
CTO at NCSC Summary: week ending November 17th
Zero-days everywhere...
01611
Reposted by Antonio Cocomazzi
Hexacorn @hexacorn.bsky.social · 16/11/2024
AdobeFips - Adobe Reader Lolbin www.hexacorn.com/blog/2024/11...
195
Reposted by Antonio Cocomazzi
Justin Elze @handle.invalid · 16/11/2024
youtu.be/-X1n3BEfzv8?...
youtu.be
BRC4 Malware Analysis and Deobfuscation (Stream - 9/11/2024)
YouTube video by Invoke RE
04912
Reposted by Antonio Cocomazzi
Hexacorn @hexacorn.bsky.social · 15/11/2024
Beyond good ol’ Run key, Part 144 www.hexacorn.com/blog/2024/11...
12310
Reposted by Antonio Cocomazzi
Costin G. Raiu @craiu.bsky.social · 15/11/2024
The Three Buddies Problem podcast episode 21 is now live! Together with @ryanaraine.bsky.social and @jags.bsky.social we talk geography, cyber magic walls, Aria Sepehr Ayandehsazan aka Emennet Pasargad, Predatory Sparrow and of course, magic money #bitcoin: securityconversations.com/episode/what...
securityconversations.com
What happens to CISA now? Is deterrence in cyber possible? - Security Conversations
Three Buddy Problem – Episode 21: We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, […]
1188
Reposted by Antonio Cocomazzi
Jamie Levy 🦉 @gleeda.bsky.social · 15/11/2024
Great work by the @volexity.bsky.social crew!
0135
Reposted by Antonio Cocomazzi
Phil Stokes ⫍🐠⫎ @philofishal.bsky.social · 15/11/2024
Bunch of new Amos/Atomic #macOS #infostealers if you pivot off ```behaviour_processes:"sh -c curl -s https[:]//api.ipify[.]org/?format=text" tag:macho``` Low detections on V(h/t x.com/malwrhuntert...) #malware #apple #cybersecurity
low detection rates on macOS Amos malware on virustotal
2237
Reposted by Antonio Cocomazzi
Jamie Levy 🦉 @gleeda.bsky.social · 15/11/2024
🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️:
A redacted view of the SafePay onion website hosting information about compromised machinesDirectory listing from the attacker's onion siteApache Server info page
23612
Reposted by Antonio Cocomazzi
Kim Zetter @kimzetter.bsky.social · 15/11/2024
France's former domestic spy chief on trial for allegedly collecting classified info for Luis Vuitton owner Bernard Arnault. Bernard Squarcini allegedly spied on a former journalist and current MP who made a documentary critical of Arnault and on Hermès, a competitor of Arnault. (archive.ph/VAocp)
telegraph.co.uk
France’s former intelligence chief accused of spying for Louis Vuitton billionaire
Bernard ‘The Shark’ Squarcini denies charges including compromising national security and misuse of public funds
26626
Reposted by Antonio Cocomazzi
ocdsec @ocdsec.bsky.social · 15/11/2024
github.com/blackorbird/...
github.com
022
Reposted by Antonio Cocomazzi
Alex Delamotte @alex.leetnoob.com · 14/11/2024
I wrote a post on the realities of cloud & webserver ransomware. Check it out to see some of the toolsets & frameworks that can be used for these attacks.
0147
Antonio Cocomazzi @splintercode.bsky.social · 14/11/2024
This MemProcFS has a lot of potentials. I have seen it also abused by some ransomware operator to dump lsass. If you see the loading of such drivers and aren’t commonly used in your environment then you should set some alerts based on that.
030
Reposted by Antonio Cocomazzi
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 14/11/2024
NEW: Security researchers confirm that iPhones running iOS 18 now automatically reboot if they are not unlocked for 72 hours. The "inactivity reboot" feature will make life harder for thieves, law enforcement, and forensic experts trying to extract data from iPhones. techcrunch.com/2024/11/14/n...
techcrunch.com
New Apple security feature reboots iPhones after 3 days, researchers confirm | TechCrunch
“Inactivity reboot" effectively puts iPhones in a more secure state by locking the user's encryption keys in the iPhone's secure enclave chip.
13615
Reposted by Antonio Cocomazzi
Justin Elze @handle.invalid · 14/11/2024
Attacking JWT with Self-Signed Claims - trustedsec.com/blog/attacki...
trustedsec.com
Attacking JWT with Self-Signed Claims
1255
Reposted by Antonio Cocomazzi
Clément Labro @itm4n.bsky.social · 11/11/2024
🆕 New blog post! "Exploiting KsecDD through Server Silos" In my latest mini research project, I've been working with my teammate @PMa1n (X) on extending the work of @floesen_ (X) on the KsecDD driver. I'm thrilled to finally share the results. 👉 blog.scrt.ch/2024/11/11/e...
blog.scrt.ch
Exploiting KsecDD through Server Silos – SCRT Team Blog
1117
Antonio Cocomazzi @splintercode.bsky.social · 13/11/2024
Hello world 👋
030