PatchRequest's profile picture. Pentesting | Red Teaming | Physical | MalDev | Game Hacking | Anti Cheat

PatchRequest

@PatchRequest

Pentesting | Red Teaming | Physical | MalDev | Game Hacking | Anti Cheat

Pinned

Currently analyzing the leaks regarding conti gang. Found a file with a Mega account. PW is in the file too. I think I should not log into it right? :D


PatchRequest reposted

Vibe Coding with AI was the best ever for Bug Bounty. The DevOps is so bad that I love it. While generating tokens, it somehow generates infosec jobs too Find more at: cerast-intelligence.com

CerastIntel's tweet image. Vibe Coding with AI was the best ever for Bug Bounty. The DevOps is so bad that I love it. 
While generating tokens, it somehow generates infosec jobs too

Find more at: cerast-intelligence.com

PatchRequest reposted

We are live! Search our database of over 8 million potentially exposed files by domain 🔍 Explore now: cerast-intelligence.com


PatchRequest reposted

Sneak Peek of what’s coming October 1st Be ready | millions of never-before-seen exposed files will become searchable cerast-intelligence.com

CerastIntel's tweet image. Sneak Peek of what’s coming October 1st

Be ready | millions of never-before-seen exposed files will become searchable

cerast-intelligence.com

Injecting a DLL into every process and overwriting WinAPI functions can easily go wrong. My anti-cheat crashed the PC with the pop-ups :) Is this technique a thing for anti-cheats? I mainly know it from EDR and AV github.com/PatchRequest/O…

PatchRequest's tweet image. Injecting a DLL into every process and overwriting WinAPI functions can easily go wrong. My anti-cheat crashed the PC with the pop-ups :)

Is this technique a thing for anti-cheats? I mainly know it from EDR and AV

github.com/PatchRequest/O…

I think scoring applications based on ProcAge, ExeAge, and their behavior is a valid approach to determine whether it’s just Task Manager requesting a handle for the billionth time or a Python CreateRemoteThread PoC github.com/PatchRequest/O…

PatchRequest's tweet image. I think scoring applications based on ProcAge, ExeAge, and their behavior is a valid approach to determine whether it’s just Task Manager requesting a handle for the billionth time or a Python CreateRemoteThread PoC

github.com/PatchRequest/O…

Second detection: when somebody requests a handle to my protected process, I can react to it. github.com/PatchRequest/O…

PatchRequest's tweet image. Second detection: when somebody requests a handle to my protected process, I can react to it.

github.com/PatchRequest/O…

Started detecting remote thread creation, pretty cool if you ask me :) At first I was confused until I realized my notify routine runs in the process context of the invoker, then it was pretty easy to detect github.com/PatchRequest/O…

PatchRequest's tweet image. Started detecting remote thread creation, pretty cool if you ask me :) 
At first I was confused until I realized my notify routine runs in the process context of the invoker, then it was pretty easy to detect

github.com/PatchRequest/O…

Cleaned up a lot of the com stuff and now I use a minifilter communication port with custom structs to send userland telemetry about: - OB callbacks (handle operations) - Process/Thread notify routines - Minifilter I/O events (create, read, write) github.com/PatchRequest/O…

PatchRequest's tweet image. Cleaned up a lot of the com stuff and now I use a 
minifilter communication port with custom structs to send 
userland telemetry about:
- OB callbacks (handle operations)
- Process/Thread notify routines
- Minifilter I/O events (create, read, write)

github.com/PatchRequest/O…

Just added screenshot capability to my Mythic agent. It captures the screen using GDI (BitBlt into a bitmap), extracts raw pixels with GetDIBits, and encodes them as PNG. Anyone know a good method to take screenshots that aren't monitored by EDRs? #maldev github.com/PatchRequest/K…

PatchRequest's tweet image. Just added screenshot capability to my Mythic agent. It captures the screen using GDI (BitBlt into a bitmap), extracts raw pixels with GetDIBits, and encodes them as PNG.
Anyone know a good method to take screenshots that aren't monitored by EDRs?
#maldev
github.com/PatchRequest/K…

Wrote a Windows kernel driver in Rust to read and write memory on request from a userland program, was pretty fun. I can recommend the Rust kernel Series from @0xfluxsec fluxsec.red

PatchRequest's tweet image. Wrote a Windows kernel driver in Rust to read and write memory on request from a userland program, was pretty fun. I can recommend the Rust kernel Series from @0xfluxsec 
fluxsec.red

Just implemented a pivot system where one agent can start listening on a port, and other agents can use that port for external connections to build redirector chains in restricted networks. It's quite fun to build a #C2 agent, I have to say :)

PatchRequest's tweet image. Just implemented a pivot system where one agent can start listening on a port, and other agents can use that port for external connections to build redirector chains in restricted networks.
It's quite fun to build a #C2 agent, I have to say :)

Just added that it can execute .NET applications in memory. Any ideas for other must-have features?

PatchRequest's tweet image. Just added that it can execute .NET applications in memory. Any ideas for other must-have features?

My Mythic Rust Agent now runs BOFs, together with the SOCKS Proxy it provides over the Teamserver it is basically able to do everything :)

PatchRequest's tweet image. My Mythic Rust Agent now runs BOFs, together with the SOCKS Proxy it provides over the Teamserver it is basically able to do everything :)

Started a few days ago writing a Mythic agent in C for fun. Made some small progress—basic callback and inline shellcode execution :) Next step: dive into @vxunderground and read some fun stuff to implement.

PatchRequest's tweet image. Started a few days ago writing a Mythic agent in C for fun. Made some small progress—basic callback and inline shellcode execution :) Next step: dive into @vxunderground  and read some fun stuff to implement.

PatchRequest reposted

Found a leaked .env file during testing today — critical reminder to check for sensitive data exposure. 🚨 Want to find it too? 👉 cerast-intelligence.com

CerastIntel's tweet image. Found a leaked .env file during testing today — critical reminder to check for sensitive data exposure. 🚨 
Want to find it too? 👉 cerast-intelligence.com

PatchRequest reposted

Super cool story about hacking hackers! 😎 Read it, learn from it, and definitely don’t try this yourself (or maybe do). 🕵️‍♂️🔥 #Infosec medium.com/@corneacristia…


PatchRequest reposted

🚨 Heads up, devs! A malicious commit hit the lottie-player repo, causing pop-ups linked to a crypto scam. If you're using it, double-check your dependencies and update ASAP! Stay sharp out there. github.com/LottieFiles/lo… #infosec #cybersecurity #Web3 #crypto #scam #lottieplayer

CerastIntel's tweet image. 🚨 Heads up, devs! A malicious commit hit the lottie-player repo, causing pop-ups linked to a crypto scam. If you're using it, double-check your dependencies and update ASAP! Stay sharp out there. github.com/LottieFiles/lo… #infosec #cybersecurity #Web3 #crypto #scam #lottieplayer…

United States Trends

Loading...

Something went wrong.


Something went wrong.