bohops
@bohops.bsky.social
π€ 105
π₯ 31
π 5
Mostly on X
reposted by
bohops
Hexacorn
5 months ago
mscoree.dll, RunDll32ShimW lolbin
www.hexacorn.com/blog/2025/05...
0
7
3
[Blog] This ended up being a great applied research project with my co-worker Dylan Tran on weaponizing a technique for fileless DCOM lateral movement based on the original work of James Forshaw. Defensive recommendations provided. - Blog:
ibm.com/think/news/f...
- PoC:
github.com/xforcered/Fo...
loading . . .
Fileless lateral movement with trapped COM objects | IBM
New research from IBM X-Force Red has led to the development of a proof-of-concept fileless lateral movement technique by abusing trapped Component Object Model (COM) objects. Get the details.
https://ibm.com/think/news/fileless-lateral-movement-trapped-com-objects
7 months ago
0
15
12
reposted by
bohops
Chris Thompson
7 months ago
I am excited to announce the first conference dedicated to the offensive use of AI in security! Request an invite at
offensiveaicon.com
. Co-organized by RemoteThreat, Dreadnode, & DEVSEC.
1
7
3
reposted by
bohops
ClΓ©ment Labro
8 months ago
In this blog post, I explain how I was able to create a PowerShell console in C/C++, and disable all its security features (AMSI, logging, transcription, execution policy, CLM) in doing so. πͺ π
blog.scrt.ch/2025/02/18/r...
2
43
21
reposted by
bohops
James Forshaw
9 months ago
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process.
googleprojectzero.blogspot.com/2025/01/wind...
loading . . .
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html
2
65
41
reposted by
bohops
Brett Hawkins
9 months ago
You can find our
@shmoocon.bsky.social
presentation slides at the below GitHub repo. Thanks again to all that attended. Also, thank you to the conference organizers for putting on a great con and having us!
#shmoocon
github.com/h4wkst3r/Con...
add a skeleton here at some point
1
16
12
you reached the end!!
feeds!
log in