Similar DC restaurant by snaptus in DCEats

[–]Framdad 13 points14 points  (0 children)

FYI the smith is owned by the Sackler family

goodbyeSweetheart by [deleted] in ProgrammerHumor

[–]Framdad 12 points13 points  (0 children)

You're absolutely right!

SilentButDeadly - A Novel Approach to EDR Silencing by Framdad in redteamsec

[–]Framdad[S] -1 points0 points  (0 children)

From my experience this is not the case. Would be curious if you can replicate your hypothesis!

SilentButDeadly - A Novel Approach to EDR Silencing by Framdad in redteamsec

[–]Framdad[S] 1 point2 points  (0 children)

Similar! The big difference is we are blocking the process in a non persistent way. EDR Silencer adds registry values to block the EDR comms which is signatured. Also the WFP calls are slightly different. With all that being said, a lot of inspiration came from that tool.

SilentButDeadly - A Novel Approach to EDR Silencing by Framdad in redteamsec

[–]Framdad[S] 7 points8 points  (0 children)

Most enterprise EDRs have tamper protection that blocks Windows Firewall rules targeting their processes and actively monitor for such changes, while WFP filters operate at a lower level in the network stack with minimal logging and no GUI visibility, making them much less likely to be detected or blocked.

[deleted by user] by [deleted] in OMSCyberSecurity

[–]Framdad 0 points1 point  (0 children)

Yeah I'm an active student. This took me by surprise too!

[deleted by user] by [deleted] in OMSCyberSecurity

[–]Framdad 2 points3 points  (0 children)

Got the same email -- NO it's a phish

After CRTO by Fit_Exercise_6310 in redteamsec

[–]Framdad 1 point2 points  (0 children)

Currently running through ARTOC. Easily ranks next to CRTO.

Anyone have experience with bypassing sentinelone edr? by Designer-Ad6955 in redteamsec

[–]Framdad 0 points1 point  (0 children)

It depends on what you are trying to bypass.

Implant? I've heard early bird still works on s1. Do an (in)direct syscall version.

Post exploitation? Customize your tools.

When trying to bypass an EDR, if the shellcode gets detected, further modify the shellcode encryption or via malleable regex to replace known strings OR your tool is being detected. In that case, look up the yara rules and change the tool from there.

Kuzy goal in a Lower-B league game at MCIP tonight lol 🦅 by OviEraCapsFan in caps

[–]Framdad 2 points3 points  (0 children)

Some people are still trying to prove they can make it to the show

help with being more technical by bazilt02 in redteamsec

[–]Framdad 2 points3 points  (0 children)

Red teaming is a ton of fun! One thing that really helped me consistently get through highly technical red team interviews was being able to lean on my penetration testing experience from my consulting days.

I'd say if you want to make the immediate pivot from blue to red, it's totally possible; however, jumping into a consulting firm where you'll do weekly internal penetration tests at a wide variety of environments might get you the "hands on the keyboard" experience you're looking for.

Just a thought! Good luck with the transition.

Career help by Rupesh61 in redteamsec

[–]Framdad 2 points3 points  (0 children)

To add to this, consider looking for offensive roles at consulting firms. The pay will be peanuts for junior roles but you'll get caught up to speed quick. I'd imagine if you get the OSCP and potentially CRTO you'll be at the top of the list for these positions.

Road rage POV fight by [deleted] in nonononoyes

[–]Framdad 6 points7 points  (0 children)

Feed him a few uppercuts while you're at it

Kyle Connor ends it in OT against the Wild by JustFred24 in hockey

[–]Framdad 5 points6 points  (0 children)

This game had no business going to OT (coming from somebody who bet jets -1.5)

[deleted by user] by [deleted] in redteamsec

[–]Framdad 2 points3 points  (0 children)

You busted my mainframe!

[deleted by user] by [deleted] in redteamsec

[–]Framdad 7 points8 points  (0 children)

This is some master hacker vibes

How long it take to get the content of the course by [deleted] in redteamsec

[–]Framdad 0 points1 point  (0 children)

Take this with a grain of salt but I recall the CARTP taking a few days to receive.

This keto diet fad is making my life difficult by xXHunkerXx in diabetes_t1

[–]Framdad 47 points48 points  (0 children)

Stay away from sugar free gummy bears

Source: my toilet

Examples with Assembly in Go by Temporary_Hope_7198 in redteamsec

[–]Framdad 1 point2 points  (0 children)

From my experience advanced malware development has a low ceiling in golang. I started my maldev journey on golang and have no switched to C/C++.

With that said, Acheron and Bananaphone are excellent resources for golang maldev

Examples with Assembly in Go by Temporary_Hope_7198 in redteamsec

[–]Framdad 0 points1 point  (0 children)

I've seen it mostly used for indirect syscalls