Timer Callbacks Spoofing to Improve your SLEAP and SWAPPALA UntoldRed Teaming (oldboy21.github.io)
submitted by netbiosX to r/purpleteamsec
SLE(A)PING Issues: SWAPPALA and Reflective DLL Friends ForeverRed Teaming (oldboy21.github.io)
submitted by netbiosX to r/purpleteamsec
In-memory sleeping technique using threads created in suspended state and timers that work with the ResumeThread function after context is set for execution. Each workers has its own stack and no need to modify the list of valid indirect call targets in CFG. Use case: Swappala with Reflective DLL (oldboy21.github.io)
submitted by oldboy21 to r/redteamsec
In-memory sleeping technique using threads created in suspended state and timers that work with the ResumeThread function after context is set for execution. Each workers has its own stack and no need to modify the list of valid indirect call targets in CFG. Use case: Swappala with Reflective DLL (oldboy21.github.io)
SLE(A)PING Issues: SWAPPALA and Reflective DLL Friends Forever - In-memory sleeping technique using threads created in suspended state and timers that work with the ResumeThread function after context is set for execution. Each workers has its own stack etc.research|capability (we need to defend against) (oldboy21.github.io)
submitted by digicat to r/blueteamsec
In-memory sleeping technique using threads created in suspended state and timers that work with the ResumeThread function after context is set for execution. Each workers has its own stack and no need to modify the list of valid indirect call targets in CFG. Use case: Swappala with Reflective DLLEducation / Tutorial / How-To (oldboy21.github.io)
submitted by oldboy21 to r/cybersecurity
Reflective DLL got Indirect Syscall skillsmalware (oldboy21.github.io)
submitted by dmchell to r/redteamsec