A series of blog posts from BHIS.
https://www.blackhillsinfosec.com/three-simple-disguises-for-evading-antivirus/
https://www.blackhillsinfosec.com/how-to-bypass-application-whitelisting-av/
https://www.blackhillsinfosec.com/click-to-enable-content/
https://www.blackhillsinfosec.com/modifying-metasploit-x64-template-for-av-evasion/
A place to share links and articles that i have found helpful. This blog tends to be more offensive security minded. Basically it is a collection of notes that I will update periodically. None of this is set in stone, and I could very well be wrong on most of it. Just saying.
Showing posts with label msfvenom. Show all posts
Showing posts with label msfvenom. Show all posts
Some fun lately with custom payloads
Doing some testing on new AV. Been reading a lot about custom payloads. I now many of these are old, but the ideas may still be new to others.
Here are some of the more recent reads ......
http://e-spohn.com/blog/2012/08/02/pe-crypters-hyperion/
https://www.christophertruncer.com/bypass-antivirus-with-meterpreter-as-the-payload-hyperion-fun/
http://www.exploit-monday.com/2011/11/powersyringe-powershell-based-codedll.html
http://colesec.inventedtheinternet.com/obfuscating-meterpreter-payloads-with-veil/
http://colesec.inventedtheinternet.com/hacking-with-powershell-powersploit-and-invoke-shellcode/
https://github.com/rapid7/metasploit-framework/wiki/How-payloads-work
https://www.citadelo.com/en/how-we-bypassed-nod32-and-hacked-a-paranoid-customer-2/
Here are some of the more recent reads ......
http://e-spohn.com/blog/2012/08/02/pe-crypters-hyperion/
https://www.christophertruncer.com/bypass-antivirus-with-meterpreter-as-the-payload-hyperion-fun/
http://www.exploit-monday.com/2011/11/powersyringe-powershell-based-codedll.html
http://colesec.inventedtheinternet.com/obfuscating-meterpreter-payloads-with-veil/
http://colesec.inventedtheinternet.com/hacking-with-powershell-powersploit-and-invoke-shellcode/
https://github.com/rapid7/metasploit-framework/wiki/How-payloads-work
https://www.citadelo.com/en/how-we-bypassed-nod32-and-hacked-a-paranoid-customer-2/
Subscribe to:
Posts (Atom)