unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Malware Source code string extraction
文章探讨了如何通过分析恶意软件源代码中的字符串和文件扩展名来快速识别潜在的恶意活动和内部威胁。通过提取独特的文件名和关注编程相关的文件扩展名,可以在短时间内发现有价值的 forensic artifacts,并用于检测恶意行为或员工违规操作。...
2025-3-30 00:16:52 | 阅读: 19 |
收藏
|
Hexacorn - www.hexacorn.com
corpora
artifacts
malicious
wins
predictable
Hunting for the warez & other dodgy stuff people install / download, part 2
文章介绍了通过搜索特定多媒体、字幕和存档文件扩展名来发现公司设备上的非法内容,并利用torrent和磁力链接追踪相关内容。然而,处理这些违规行为需谨慎,通常被视为低优先级风险,并可能涉及内部人员违规。...
2025-3-8 22:19:50 | 阅读: 1 |
收藏
|
Hexacorn - www.hexacorn.com
referencing
pirated
subtitle
7z
station
Hunting for the warez & other dodgy stuff people install / download, part 1
文章探讨了员工在公司内部安装盗版或可疑软件的问题及其带来的安全风险。尽管实施了严格政策和关键词监控,但误报和复杂环境仍使管理困难。建议通过分析日志中的特定关键词及利用公开资源优化检测机制。...
2025-3-1 00:30:33 | 阅读: 4 |
收藏
|
Hexacorn - www.hexacorn.com
software
keygen
telemetry
pirated
cracking
DeXRAY v2.35
DeXRAY 更新版本新增 Fortinet 隔离文件支持,基于 maldump 研究,感谢 TheMythologist 和研究人员。...
2025-2-24 22:58:55 | 阅读: 9 |
收藏
|
Hexacorn - www.hexacorn.com
maldump
download
dexray
guys
String analysis for n00bs
文章介绍了一个Windows可执行文件的反向工程案例。静态和动态分析显示其功能简单(输出"Hello World!"),但代码分析揭示了隐藏功能:当传入特定参数(如"/h")时会输出"Hello Baby!!"。这提醒我们不能盲目依赖自动化工具,需深入分析以发现潜在分支或隐藏行为。...
2025-2-23 14:6:52 | 阅读: 4 |
收藏
|
Hexacorn - www.hexacorn.com
analysis
blindly
payload
printed
locale
Good Exports are real
2025-2-22 23:24:56 | 阅读: 4 |
收藏
|
Hexacorn - www.hexacorn.com
Optimizing the regexes, or not
文章讨论了如何通过正则表达式匹配大量已知干净内核驱动文件名的问题,并尝试使用Regexp::Optimizer模块生成高效且精确的正则表达式。尽管实现了51%的压缩率,但复杂性过高导致调试困难,并反思正则表达式可能并非最佳解决方案。...
2025-2-22 10:57:31 | 阅读: 6 |
收藏
|
Hexacorn - www.hexacorn.com
gave
solving
kinda
trie
5k
The rapidly changing geopolitics and its inevitable effect on cyber
"跟着太阳走"的信息共享模式已失效,国际组织间不再开放分享关键情报,甚至"五眼联盟"也难再合作。随着美国政治剧变,全球网络安全格局将发生巨变,过去由西方民主国家主导的"好人"集体不复存在。企业需迅速调整,采用地区化数据管理、分散安全运营中心等措施,但这将带来巨大挑战和成本。...
2025-2-21 22:18:22 | 阅读: 4 |
收藏
|
Hexacorn - www.hexacorn.com
guys
gonna
dramatic
suggested
fedramp
DWRCSAccess.log artifact
文章介绍了 DameWare 的 DWRCSAccess.log 文件,该文件记录远程控制事件的本地化消息和英文元数据。消息包括用户连接、断开及认证失败等信息;元数据包含详细系统和安全信息,可能对攻击者分析有用。...
2025-2-5 23:29:47 | 阅读: 7 |
收藏
|
Hexacorn - www.hexacorn.com
proxy
localized
benutzer
Files of interest
I really like this MalBeacon’s project because it highlights how easy it is to detect many...
2025-1-31 00:50:10 | 阅读: 13 |
收藏
|
Hexacorn - www.hexacorn.com
telemetry
unlimited
families
comb
watermarked
Being a tool while using a tool
This case is kinda DFIR-fascinating.There is an unwritten rule in the DFIR world that says –...
2025-1-25 01:22:29 | 阅读: 11 |
收藏
|
Hexacorn - www.hexacorn.com
7z
pluginsdir
analysis
nsi
huh
Smuggling payloads and tools in, using WIM images, Part 2
In this post we explore the dism.exe and WIM images a bit more. It turns out that WIM files...
2025-1-1 00:9:30 | 阅读: 7 |
收藏
|
Hexacorn - www.hexacorn.com
wim
newtest
lowpart
highpart
dism
Clean hash set – 12M rows
The file contains 12M+ of rows, each containing a set of popular hashes, and a file name ex...
2024-12-31 18:31:56 | 阅读: 5 |
收藏
|
Hexacorn - www.hexacorn.com
software
watermarked
firmwares
unlimited
dome
Smuggling payloads and tools in, using WIM images
We often hear of attackers bringing in their payloads via virtual drive images (f.ex. vhd,vhdx)...
2024-12-31 00:20:44 | 阅读: 8 |
收藏
|
Hexacorn - www.hexacorn.com
wim
mounted
lowpart
totalbytes
highpart
WIMMOUNTDATA ADS
In my old post I listed a number of ‘good Alternate Data Streams (ADS)’, and one of them wa...
2024-12-28 23:32:9 | 阅读: 8 |
收藏
|
Hexacorn - www.hexacorn.com
dism
wim
imagefile
3908
MoNotificationUxStub.exe lolbin
When you run MoNotificationUxStub.exe on Windows Server 2025, it will try to load the follo...
2024-12-27 00:16:22 | 阅读: 10 |
收藏
|
Hexacorn - www.hexacorn.com
windows
library
uus
umpdc
MLEngineStub.exe lolbin
When you run MLEngineStub.exe on Windows 2025, it will try to locate the following non-exis...
2024-12-27 00:7:47 | 阅读: 9 |
收藏
|
Hexacorn - www.hexacorn.com
windows
uus
mlengine
caveat
la57setup.exe & OOBEFodSetup.exe lolbin
When you run la57setup.exe or OOBEFodSetup.exe on Windows Server 2025, they will try to loa...
2024-12-26 23:44:11 | 阅读: 6 |
收藏
|
Hexacorn - www.hexacorn.com
windows
library
dism
la57setup
3 little secrets of netsh.exe
It is typical for many of us to discover ‘the cool thing’, and then quickly move on to research...
2024-12-25 23:15:42 | 阅读: 5 |
收藏
|
Hexacorn - www.hexacorn.com
netsh
scriptfile
aliasfile
lolbin
careful
Windows Server 2025 and MsMpEng.exe
Post navigation← PreviousPosted on 202...
2024-12-22 00:37:54 | 阅读: 16 |
收藏
|
Hexacorn - www.hexacorn.com
windows
defender
repeat
waaaay
Previous
1
2
3
4
5
6
7
8
Next