unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Honeypot Notes Part 3 - endpoint data
Intro(No AI was involved in writing, research, etc...)See part 1 and 2 here: https://www.boredhacke...
2026-8-5 21:24:37 | 阅读: 9 |
收藏
|
boredhackerblog - www.boredhackerblog.info
honeypot
network
software
collecting
Honeypot Notes Part 2 - network data
Intro(No AI was involved in writing, research, etc...)Read part 1 here:https://www.boredhackerblog....
2026-8-5 21:20:17 | 阅读: 13 |
收藏
|
boredhackerblog - www.boredhackerblog.info
honeypot
outbound
suricata
attacker
payload
Honeypot Notes Part 1 - deployment/design
Intro(No AI was involved in writing, research, etc...)Note: this blog is titled "Honeypot Notes" be...
2026-8-5 21:14:18 | 阅读: 11 |
收藏
|
boredhackerblog - www.boredhackerblog.info
honeypot
software
honeypots
network
rinetd
Doing malware research without spending money
Just doing a quick write up of tools I use to do malware/threat research for free. Most of the time...
2026-7-31 21:36:51 | 阅读: 31 |
收藏
|
boredhackerblog - www.boredhackerblog.info
analysis
censys
pivoting
anyrun
github
REDCap exploitation in 2023
IntroI saw Google Threat Intelligence teams article regarding REDCap exploitation here: Public and...
2026-6-20 02:27:7 | 阅读: 37 |
收藏
|
boredhackerblog - www.boredhackerblog.info
redcap
exploited
php
gtig
crowdstrike
How Unifi OS exploitation may have happened
Note: if images or formatting is broken, blame Blogger. (from discord)What's going on?Last week w...
2026-6-5 03:57:12 | 阅读: 44 |
收藏
|
boredhackerblog - www.boredhackerblog.info
unifi
reddit
udr7
sso
Use of MQTT in malware part 2: quick analysis
Note: I've had limited time to work on this. I took some time off to finish some training but wan...
2026-6-2 17:44:55 | 阅读: 33 |
收藏
|
boredhackerblog - www.boredhackerblog.info
analysis
abilities
python
broker
vt
Use of MQTT in malware
I'm alive but very busy!! It's been 10 years since I started this blog.Changed the blog theme to da...
2026-6-2 17:44:26 | 阅读: 44 |
收藏
|
boredhackerblog - www.boredhackerblog.info
mqtt
broker
brokers
analysis
wailingcrab
Use of Tox protocol in malware
2024-9-22 08:41:0 | 阅读: 23 |
收藏
|
boredhackerblog - www.boredhackerblog.info
Progressive Web Apps (PWA) on Windows - forensics and detection of use
IntroductionProgressive Web app (PWA) is just a webapp that can be installed as an app on a system...
2024-6-20 09:11:0 | 阅读: 38 |
收藏
|
boredhackerblog - www.boredhackerblog.info
chrome
pwa
progressive
phishing
microsoft
observed in the wild - batch obfuscation technique and an interesting way to run powershell code
Saw these two things in the wild while looking at some samples.Batch ObfuscationMalicious batch fil...
2024-3-24 07:27:0 | 阅读: 38 |
收藏
|
boredhackerblog - www.boredhackerblog.info
powershell
oneconsult
inferably
55257
Speeding up report reading and security/SOC alert triaging by auto-highlighting keywords on webpages
Introduction:If you're a security analyst or threat researcher, you may spend a lot of time reading...
2023-12-22 01:33:0 | 阅读: 16 |
收藏
|
boredhackerblog - www.boredhackerblog.info
github
customize
finds
Quick sample analysis which ended up dropping asyncrat
I came across a sample that involving traffic to 91.92.242.28:222.There is sandbox report here: ht...
2023-11-18 08:52:0 | 阅读: 28 |
收藏
|
boredhackerblog - www.boredhackerblog.info
tron
coment
launching
microsoft
powershell
Using command line redirection and DLL ordinals to potentially bypass detections
I came across this during a pentest. The techniques mentioned here are not new and there are alread...
2023-10-23 02:33:0 | 阅读: 41 |
收藏
|
boredhackerblog - www.boredhackerblog.info
comsvcs
ntds
attacker
rundll32
minidump
Installing Whonix Gateway on Proxmox for threat & malware research
IntroWhonix is a tool for routing traffic through Tor. Whonix VM's come as Desktop/with UI or CLI....
2023-10-8 01:32:0 | 阅读: 92 |
收藏
|
boredhackerblog - www.boredhackerblog.info
whonix
network
proxmox
152
wiki
OpenSSL-1.0.0-fipps Linux Backdoor - Notes
Introduction:In some security/malware chat room, someone posted about an ELF backdoor, at the time,...
2022-11-30 06:39:0 | 阅读: 28 |
收藏
|
boredhackerblog - www.boredhackerblog.info
c2
fipps
submission
sysv
Looking for EvilProxy - Notes
Introduction:This started with someone asking about EvilProxy and any signatures for detecting it....
2022-11-22 05:35:0 | 阅读: 23 |
收藏
|
boredhackerblog - www.boredhackerblog.info
evilproxy
urlscan
phishing
444
lmo
Researching golang malware and how I hate security industry naming conventions - Part 1
While doing some research on the use of golang in malware, I came across this golang sample here: h...
2022-10-17 23:11:0 | 阅读: 28 |
收藏
|
boredhackerblog - www.boredhackerblog.info
gotroj
gsh
winservice
darkdoor
Researching golang malware and how I hate security industry naming conventions - Part 2
I did some string searches in Hybrid-Analysis as well to look for more files. (Thanks Hybrid-Analys...
2022-10-17 23:11:0 | 阅读: 26 |
收藏
|
boredhackerblog - www.boredhackerblog.info
c2
analysis
filesize
181
0x5a4d
Looking at process relationships from malware sandbox execution data
Introduction:This blog post discusses looking at process relationships, specifically from malware s...
2022-10-16 01:42:0 | 阅读: 23 |
收藏
|
boredhackerblog - www.boredhackerblog.info
analysis
database
ilike
commandline
Previous
-4
-3
-2
-1
0
1
2
3
Next