Last Week in Security (LWiS) - 2025-09-22
文章总结了近期网络安全新闻与技术进展,包括NPM重大漏洞、微软云身份验证漏洞、WebSocket安全测试工具及Linux内核漏洞等。同时介绍了EDR-Freeze、Linux Kernel Guard等工具与技术。 2025-9-23 04:7:59 Author: blog.badsectorlabs.com(查看原文) 阅读量:26 收藏

Getting Global Admin in every Entra tenant (@_dirkjan), WebSocket Turbo Intruder (@zakfedotkin), PureRAT analysis (@Tera0017), direct syscalls in Zig (@zux0x3a), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-09-15 to 2025-09-22.

News

Techniques and Write-ups

Tools and Exploits

  • EDR-Freeze - EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.
  • WMI_Proc_Dump - Dump processes over WMI with MSFT_MTProcess.
  • mtprocess - Python script to leverage MSFT_MTProcess WMI class.
  • Linux Kernel Runtime Guard (LKRG) 1.0 is a Linux kernel module that performs runtime integrity checking of the kernel and detection of security vulnerability exploits against the kernel, prevention of and response to successful attacks, and encrypted remote logging.
  • google-redirector - A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure. See: Domain Fronting is Dead. Long Live Domain Fronting! (not to be confused with my DEF CON 28 talk [PDF] Domain Fronting is Dead, Long Live Domain Fronting)
  • TTPx - Red Team reporting and analytics platform.
  • Ouroboros - Decompiler written in Rust.
  • Introducing KSON - "Anywhere a human is reading or editing YAML/JSON/TOML, KSON may be used as a more effective interface on that data." KSON is a superset of JSON but written like YAML.
  • TaskHound - Tool to enumerate privileged Scheduled Tasks on Remote Systems.
  • auditkit - Open source SOC2 compliance scanner - Alternative to $20k/year tools.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • ZigStrike - ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.
  • like-dbg - Fully dockerized Linux kernel debugging environment.
  • Ghost in the Script: Impersonating Google App Script projects for stealthy persistence - "Apps Script projects can serve as stealthy persistence mechanisms if left unmonitored. Attackers can impersonate them to hide cryptomining, privileged service accounts, or other malicious resources inside your environment."
  • Get-NetNTLM - Internal Monologue BOF.
  • arcane - Modern Docker Management, Designed for Everyone.
  • withoutbg - Open source image background removal model.

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-09-22.html
如有侵权请联系:admin#unsafe.sh