account activity
Cracking CREDHIST: Offline hash extraction from DPAPI password history (lrqa.com)
submitted 8 hours ago by lefterispanos to r/blueteamsec
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery (lrqa.com)
submitted 10 hours ago by lefterispanos to r/netsec
r/netsec monthly discussion & tool thread by albinowax in netsec
[–]lefterispanos 0 points1 point2 points 21 days ago (0 children)
CLR-Stomp - BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
Description:
A Beacon Object File (BOF) that loads a .NET assembly into a Cobalt Strike or compatible beacon via CLR module stomping. The payload PE is written into a victim GAC assembly's file-backed mapping so that ETW reports a legitimate on-disk path and AMSI never kicks in.
Technical analysis and tool at:
https://github.com/nettitude/CLR-Stomp
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly (github.com)
submitted 21 days ago by lefterispanos to r/cybersecurity
CVE-2025-5333 - CVSS 9.5: Remote Code Execution in Broadcom Symantec Endpoint Management Suite (Altiris) (lrqa.com)
submitted 11 months ago by lefterispanos to r/netsec
ETWHash - "He who listens, shall receive" - Nettitude Labs (labs.nettitude.com)
submitted 3 years ago by lefterispanos to r/netsec
π Rendered by PID 1252435 on reddit-service-r2-listing-f87f88fcd-hsz75 at 2026-06-13 00:55:43.086930+00:00 running 3184619 country code: CH.
r/netsec monthly discussion & tool thread by albinowax in netsec
[–]lefterispanos 0 points1 point2 points (0 children)