20 Feb 2026, 17:54 UTC277 views5 reactionsread 8 August 2026 🔓 Restore case sensitive password from LM hash
Once upon a time you got LM hash. You know it's extremely insecure and easy to crack. Several minutes later these favourite characters appear: Cracked.
You're trying to log in, but creds are invalid. Typo? Copy and paste again - still no luck.
The root cause lies in LM hash computation mechanism: password is padded with null bytes to length 14, then converted to upper…
🔥5
4 Jul 2025, 07:18 UTC602 views4 reactionsread 8 August 2026 Photo
🟦 PowerShell | Get extended service details ⚙️
Exploring services via services.msc is ridiculous: no info about
- Process Id
- Command Line
- User under which a service is configured to run.
Task Manager can display missing pid field, but still lacks of user and CommandLine parameters.
🤖One more thing to take into account: automatization. If we want to automate working routine, GUI isn't the right tool for that an…
👍2🔥2
16 Apr 2025, 13:20 UTC≈1,650 views13 reactionsread 8 August 2026 Photo
📖 Burning Books | Flibusta
Today I discovered malicious campaign focused on book lovers. The popular "free" books collection flibusta[.]is has a strong evil twin flibusta[.]su
All books no matter of file format have the same size and distributed as .zip archive.
The archive is 89.3 MB large and contains two files:
<book_name>.pdf - Archive.exe
SbieDll.dll
The process first asks for UAC and then:
1️⃣ Stops EventLo…
⚡6🔥4😎2👻1
2 Apr 2025, 14:07 UTC667 views6 reactionsread 8 August 2026 Video
⛓️ Linux | Dependency chain attack for persistence
Abuse motd/apt/dpkg to periodically execute your code is a good idea, but it can be quickly detected, because file creation/modification in well-known folders for persistence is suspicious.
However, some built-in scripts launch other scripts that are usually outside the monitoring scope. So a pentester can find these scripts and extend their functionality.
🟥 Attac…
🔥3👍1👏1😎1
19 Mar 2025, 11:15 UTC≈3,450 views14 reactionsread 8 August 2026 Photo
💧 SDDL — Save your tears for another day
How many times have you strained your eyes trying to understand ACL in Windows? For example
O:BAG:SYD:(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x3;;;BO)(A;;0x5;;;SO)(A;;0x1;;;IU)(A;;0x3;;;SU)(A;;0x1;;;S-1-5-3)(A;;0x2;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)
means
1️⃣ O:BA - Owner "Built-in administrators"
2️⃣ G:SY - Group "Local System"
3️⃣ Last part - DACL.
Let's decrypt some part of DA…
🔥6⚡4❤4
7 Mar 2025, 07:36 UTC540 views3 reactionsread 8 August 2026 Video
♻️ Windows | Rest in $Recycle.Bin | Part 2
For more details see original post
function Build-Metadata{
$header = [byte[]](2,0,0,0,0,0,0,0)
$outFile = Read-Host 'Filename to save fake metadata'
$filePath = Read-Host 'File path to spoof (Original Location)'
$bFilePath = [System.Text.Encoding]::Unicode.GetBytes($filePath)
$size = Read-Host 'File size (bytes)'
$bSize = [System.BitConverter]::G…
🔥3
7 Mar 2025, 07:35 UTC486 views5 reactionsread 8 August 2026 Video
♻️ Windows | Rest in $Recycle.Bin
After death all files go to Recycle Bin: a place where no one can disturb them, but only restore or delete forever...
But using PowerShell we can access these files in additional ways: execute, modify data and even restore to the location it had never been before!
▶️ FIle execution works in the same way as for any "normal" exe, just type full path and hit Enter
C:\$Recycle.Bin\<SI…
🔥4❤1
5 Nov 2024, 12:37 UTC≈6,230 views7 reactionsread 8 August 2026 Video
💀 Windows | Get passwords no one notices 🔑
- Run mimikatz to steal passwords? — No way!
- Capture RAM using forensics tools, exfiltrate it and process remotely? — Better, but blue team will knock you down anyway (your user isn't a forensics specialist, huh?)
🥷🏻How to get RAM snapshot quieter
- When Windows faces a problem that it can't recover from safely, it shows BSoD and saves the current RAM state to
C:\Windows…
🔥7
9 Sept 2024, 11:49 UTC805 views2 reactionsread 8 August 2026 File
📂 AD | Move laterally even if the user has been blocked | Script 🚫
Notes:
1️⃣ Rubeus must be installed
2️⃣ AV/EDR must be disabled (for Rubeus to work)
3️⃣ PowerShell ActiveDirectory module must be installed. Click here to see the instructions
#persistence #redteam #kerberos #script
👍2
9 Sept 2024, 11:49 UTC731 views3 reactionsread 8 August 2026 Video
📂 AD | Move laterally even if the user has been blocked 🚫
Imagine you caught an adversary and blocked its account in Active Directory. But the attacker still can access resources in AD. How is it possible?
1️⃣ TGT < 20 minutes old
KDC doesn't validate the user specified in TGT as long as TGT < 20 minutes old
2️⃣ Cached tickets (10 hours lifetime by default)
A user can access services using valid service tickets be…
🔥3
6 Aug 2024, 07:22 UTC603 views5 reactionsread 8 August 2026 Video
✈️ Telegram | User identity takeover 🎭
Imagine you want drastically change your life and start with telegram username.
Now all your previous mentions via @ return
Username <username> not found
⁉️ But what would happen if someone TAKE your old FREE username? Should OLD links return NOTHING ⁉️
👉 Well, NO!
All the links no matter how old they are will point to the new user. That means digital identity can be stolen…
🔥3👻2
6 Jul 2024, 08:16 UTC586 views4 reactionsread 8 August 2026 Photo
💠 Windows | Run INTERACTIVE cmd with SYSTEM privileges 👑
How to execute commands with highest privileges on the local PC easy? Of course, you can execute a single command via schatasks or services, but these methods are not fast and convenient. I like these:
🟢 PsExec
PsExec.exe -s -i powershell.exe
Requirements:
- Network share must be enabled
🟢 Process Hacker
1) Click on "Hacker" tab
2) Run as...
3) Choose a Prog…
🔥3⚡1
Showing the 12 most recent of 18 posts we hold for @DefenseEvasion. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.