Sign in

Wietze

@wietzebeukema.nl
188 followers 60 following 43 posts

Threat Detection & Response. Interested in cyber security, tech and politics. Views are my own, unless retweeted.

PostsRepliesMedia
Wietze @wietzebeukema.nl · 16/06/2026
🫯 New entry added to the #LOLBAS Project: Proxy execution via system-native scp.exe. Takes any remote destination, doesn't actually have to run an SSH server. 👉 lolbas-project.github.io/lolbas/Binar... Thanks @BinFault
110
Wietze @wietzebeukema.nl · 04/06/2026
wow I set Windows to British English and everything looks different
110
Wietze @wietzebeukema.nl · 01/06/2026
HijackLibs.net just got a visual refresh 🌟 Explore 600+ documented DLL Hijacking cases, including: • JSON/CSV/YAML feeds • Sigma detection content for every DLL • A single Sigma rule covering all DLLs Check it out: hijacklibs.net
000
Wietze @wietzebeukema.nl · 01/04/2026
🆕 Recent additions to LOLBAS-Project.github.io: • sigverif/odbcad32.exe for UAC bypass via GUI • IntelliTrace/dxcap/logger.exe for proxy execution • cmstp.exe for loading arbitrary DLLs • cipher.exe for impairing defences ⭐ Nearly 8,500 GitHub stars - thank you all!
031
Wietze @wietzebeukema.nl · 16/03/2026
🔥 macOS cmd-obfuscation with ArgFuscator New: over 60 os-native macOS binaries' command lines can now be obfuscated using #ArgFuscator, bypassing command-line based detections, such as this EDR trying to prevent credential dumping. 👉 Check it out: argfuscator.net
011
Wietze @wietzebeukema.nl · 09/03/2026
Yet another LNK spoofing flaw: executes any DLL, including remote via WebDAV. Even worse, without Feb 2026 updates, MotW will be ignored. Next to updating, your best defence is to look for RunDLL32+Shell32+Control_RunDLL with non-standard targets. See how this works on github.com/wietze/lnk-i...
100
Reposted by Wietze
datariot.bsky.social @datariot.bsky.social · 13/02/2026
TIL from @wietzebeukema.nl 🤯
011
Wietze @wietzebeukema.nl · 13/02/2026
Can LNK files ever be trusted? ⚡ My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces a tool to create your own LNKs, and a tool to detected spoofed ones yourself. 🐬 www.wietzebeukema.nl/blog/trust-m...
142
Reposted by Wietze
John Hammond @johnhammond.bsky.social · 11/07/2025
Video demo to play with ArgFuscator -- the super cool research and utility from @Wietze to obfuscate command-lines to try and evade AV or EDR detection 😎 And to test your rules if any of these crazy looking commands fly under the radar! youtu.be/6-Gbv0h7m1I
171
Wietze @wietzebeukema.nl · 30/06/2025
As June comes to an end, so does #HuntingTipOfTheDay. I hope you enjoyed them! 👉 Find all of them here: bsky.app/search?q=fro...
020
Wietze @wietzebeukema.nl · 27/06/2025
#HuntingTipOfTheDay: you know how to spot/decode Base64 or XOR in PowerShell… but what about SecureString? This AES-based encryption is native to PowerShell; attackers have been seen to use this for PowerShell obfuscation. 🔍 Hunt for known SecureString decoding commands
031
Wietze @wietzebeukema.nl · 26/06/2025
#HuntingTipOfTheDay: Stuck in vi/vim? Open a reverse shell to exit remotely 🙃 Not just a joke - you can make vi/vim run arbitrary commands, not all methods to do so are well detected. 🔍 Hunt for child processes of vi(m), especially those that are rare in your environment.
030
Wietze @wietzebeukema.nl · 25/06/2025
#HuntingTipOfTheDay: there are numerous open-source projects listing cyber threats. Some of these have directly ingestible indicators, which can be very helpful when threat hunting. How about: 🔵 lots-project.com + LOLBINs 🟠 hijacklibs.net + DLL write events 🟢 lolrmm.io + DNS requests
010
Wietze @wietzebeukema.nl · 24/06/2025
#HuntingTipOfTheDay: AppleScript via osascript is still a popular way for infostealers to get credentials/escalate access. Although some (poorly coded) updaters use this ""legitimately"", hunting for osascript referencing password dialogs might surface behaviour of interest.
000
Wietze @wietzebeukema.nl · 23/06/2025
#HuntingTipOfTheDay: USB worms are still a thing - often the initial infection happens when a user clicks a malicious shortcut on a USB device. See if you can correlate executions with .LNK files on remote drives to find possible badness.
000
Wietze @wietzebeukema.nl · 20/06/2025
#HuntingTipOfTheDay: proxy execution via ComputerDefaults.exe by setting this registry key; as it auto-elevates, it also allows for UAC bypass (!). 🔴 Executing parent is usually explorer.exe, making detection harder 🔍 Hunt for reg changes to this key 👉 lolbas-project.github.io/lolbas/Binar...
011
Wietze @wietzebeukema.nl · 19/06/2025
#HuntingTipOfTheDay: Florian is right. 🌩️ Cloud creds often linger in Environment Variables, especially on servers/dev machines 🟠 One compromised endpoint could thus lead to a full cloud breach 🔍 Hunt for exposed tokens - if you can see it, so could an attacker (well, kinda)
010
Wietze @wietzebeukema.nl · 18/06/2025
#HuntingTipOfTheDay: Oddvar Moe of @trustedsec.com shows how you can run a full C2 implant from Outlook - just setting a few registry keys does the trick. Any activity concerning these registry keys should be consider suspicious. Full story here: youtu.be/7MDHhavM5GM
010
Wietze @wietzebeukema.nl · 17/06/2025
#HuntingTipOfTheDay: TCC on macOS can be bypassed by triggering Electron apps' Node.js interface to run arbitrary commands ⚡ By using a Launch Daemon, you can leverage all the app's TCC permissions 🔍 Hunt for processes with ELECTRON_RUN_AS_NODE env var and unusual command lines
120
Wietze @wietzebeukema.nl · 16/06/2025
#ThreatHuntingTipOfTheDay: rundll32 can be abused in many ways lolbas-project.github.io#t1218.011 Instead of exports, ordinals can be used too. You could hunt for known bad ones, but are ordinals used legitimately that often at all? Look for rundll32 with # on the command line to find out
000
Wietze @wietzebeukema.nl · 13/06/2025
#HuntingTipOfTheDay: folders with trailing spaces can be created on Windows, and they cause trouble: 🔴 Hard to delete/rename 🟠 Can hide (malicious) content when the same folder without trailing space exists 🟡 May enable UAC bypass (see next msg) 🔍 Hunt for paths with trailing spaces - highly sus
100
Wietze @wietzebeukema.nl · 12/06/2025
#HuntingTipOfTheDay: you’ll know that in Linux, files with a leading dot are hidden by default. Attackers may use this to hide payloads or frustrate forensics. Although sometimes used legitimately, you may find unexpected entries when looking for EXECUTIONS of hidden files.
110
Wietze @wietzebeukema.nl · 11/06/2025
#HuntingTipOfTheDay: a personal favourite, command-line obfuscation. Substituting or inserting special Unicode characters might allow attackers to bypass string-based detections. Look for command lines with unusual Unicode characters. Checkout ArgFuscator.net for more fun!
031
Wietze @wietzebeukema.nl · 10/06/2025
#HuntingTipOfTheDay: macOS has a built-in SSH mechanism that is disabled by default. Would you detect it if someone enables it and logs in remotely? Look for remote login events, and investigate the associated session.
031
Wietze @wietzebeukema.nl · 09/06/2025
#HuntingTipOfTheDay: Services can provide persistence. Looking for changes to their commands is common, but the lesser known Environment setting is often overlooked. It could result in stealthy DLL hijacking. Inspect any paths referenced for suspicious files.
232
Wietze @wietzebeukema.nl · 06/06/2025
#HuntingTipOfTheDay: explorer.exe /root,"c:/your/executable.exe" will spawn your exe from the main explorer.exe, not a new one. This breaks normal process chains. Hunt for explorer.exe with "/root", as well as explorer spawning unusual children (e.g. rundll32, mshta, powershell).
010
Wietze @wietzebeukema.nl · 05/06/2025
#HuntingTipOfTheDay: a common way to execute malicious code on Linux is to download a script via curl/wget and pipe the result into a shell process like bash. Hunt for curl/wget executions followed by an interactive shell within seconds, both having the same parent process.
010
Wietze @wietzebeukema.nl · 04/06/2025
#HuntingTipOfTheDay: You have probably heard of .bash_profile and .zshrc, but are you familiar with PowerShell's version of it? Attackers might use this for persistence; monitor modifications of profiles by unexpected processes, and analyse existing files for anomalies.
332
Wietze @wietzebeukema.nl · 03/06/2025
#ThreatHuntingTipOfTheDay: Malicious DMGs/PKGs are currently the most popular way for macOS infostealers to get foothold. Use macOS’s kMDItemWhereFroms extended attribute to see origins of downloaded DMG/PKGs; investigate ones that are rare across your IT estate.
010
Wietze @wietzebeukema.nl · 02/06/2025
A brand new month, time to bring back #HuntingTipOfTheDay as originally started by John Lambert! I’ll be posting threat hunting ideas every weekday this month - covering Windows, Linux and macOS. Find the first one below 👇
100
Reposted by Wietze
CyberRaiju @jaiminton.com · 09/05/2025
HijackLibs.net details hundreds of publicly disclosed DLL Hijacking opportunities. With over 700 stars on GitHub and a growing list, @wietzebeukema.nl does an amazing job maintaining it. Despite this contributing can be time consuming. That's why I've created HijackLibs Helper!👇
131
Wietze @wietzebeukema.nl · 22/04/2025
MITRE ATT&CK v17 is out! It contains an update I have campaigned for since 2022: DLL Hijacking is now a single sub-technique, merging Search Order Hijacking & Sideloading, plus supporting related techniques. Huge thanks & congrats to the @attack.mitre.org team on this release 🎉
A screenshot of a 2022 presentation about DLL Hijacking, defining it as "tricking a legitimate/trusted application into loading an arbitrary DLL".
130
Wietze @wietzebeukema.nl · 24/03/2025
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi...
13619
Reposted by Wietze
John Hammond @johnhammond.bsky.social · 04/03/2025
DLL hijacking with the native and built-in Windows utility Dism.exe -- simple MessageBox and obligatory reverse shell demo, then some handy penetration testing resources for tricks and opportunities with other programs :) youtu.be/uY8BpZBF2f0
2242
Wietze @wietzebeukema.nl · 18/02/2025
Thanks to @cyberbuff (buff.ly/40VgTAs) you can now leverage ArgFuscator.net's contents via Invoke-ArgFuscator. Simply install the latest version from the PowerShell Gallery and use '-Command' to specify any of the supported commands (buff.ly/4hKMjRq). 🤘 buff.ly/4b7uwBo
011
Wietze @wietzebeukema.nl · 06/02/2025
🚀 Today I'm launching ArgFuscator: an open-source platform documenting command-line obfuscation tricks AND letting you generate your own 🔥 68 commonly used executables supported out of the box - use right away, make tweaks, or create your own config 👉 Now available at argfuscator.net
061
Wietze @wietzebeukema.nl · 29/01/2025
Seen in the wild by Red Canary: Tangerine Turkey worm dropping #HijackLib printui.dll in C:\Windows \System32 (yes, with a space after 'Windows') This bypasses UAC (!) and runs malicious code via signed Microsoft binary printui.exe ⚙️ hijacklibs.net/entries/micr... 🐦 redcanary.com/blog/threat-...
141
Wietze @wietzebeukema.nl · 28/01/2025
#LOLBAS project update: Entries now have placeholders for paths, URLs, and more. This makes it easier to visually see what parts are "variable", and for LOLBAS API users (lolbas-project.github.io/api/) it'll be easier to use with automation. Check it out: ⭐ lolbas-project.github.io
0136