chromiumring's profile picture. Security Researcher/Developer

Phillipp Eisenhower

@chromiumring

Security Researcher/Developer

Phillipp Eisenhower 已轉發

Part 1: SSH Tunnels Deep Dive - Local Port Forwarding (+labs) Most people only use SSH for logging into a remote machine, and they never look beyond that. But SSH can do far more than provide a secure shell. One of its most powerful but overlooked features is tunneling, the…

sysxplore's tweet image. Part 1: SSH Tunnels Deep Dive - Local Port Forwarding (+labs)

Most people only use SSH for logging into a remote machine, and they never look beyond that. But SSH can do far more than provide a secure shell. One of its most powerful but overlooked features is tunneling, the…

Phillipp Eisenhower 已轉發

Malware development Basics - How EDRs work, Effective techniques to circumvent them and How to compensate for EDR protection gaps.. conference.hitb.org/hitbsecconf202…

5mukx's tweet image. Malware development Basics - How EDRs work, Effective techniques to circumvent them and How to compensate for EDR protection gaps.. 

conference.hitb.org/hitbsecconf202…

Phillipp Eisenhower 已轉發

I presented on WinGet Configuration at Microsoft Ignite. For those of you working on WinGet Configuration files, you might be interested in an experimental tool we're working on. ignite.microsoft.com/sessions/BRK335 `winget install wingetstudio` github.com/microsoft/wing… Documentation…


Phillipp Eisenhower 已轉發

You don't necessarily need networking to connect to your Linux VM. No IP addresses. No SSH keys. No firewall rules. No routing tables. If you are on the same physical machine, TCP/IP can be just overhead. Meet AF_VSOCK. It’s a special address family in the Linux kernel…

popovicu94's tweet image. You don't necessarily need networking to connect to your Linux VM.

No IP addresses. No SSH keys. No firewall rules. No routing tables.

If you are on the same physical machine, TCP/IP can be just overhead.

Meet AF_VSOCK.

It’s a special address family in the Linux kernel…
popovicu94's tweet image. You don't necessarily need networking to connect to your Linux VM.

No IP addresses. No SSH keys. No firewall rules. No routing tables.

If you are on the same physical machine, TCP/IP can be just overhead.

Meet AF_VSOCK.

It’s a special address family in the Linux kernel…
popovicu94's tweet image. You don't necessarily need networking to connect to your Linux VM.

No IP addresses. No SSH keys. No firewall rules. No routing tables.

If you are on the same physical machine, TCP/IP can be just overhead.

Meet AF_VSOCK.

It’s a special address family in the Linux kernel…

Phillipp Eisenhower 已轉發

VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) by Alexander Zaviyalov (@NCCGroupInfosec) nccgroup.com/media/b2chcbti… #infosec

0xor0ne's tweet image. VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) by Alexander Zaviyalov (@NCCGroupInfosec)

nccgroup.com/media/b2chcbti…

#infosec
0xor0ne's tweet image. VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) by Alexander Zaviyalov (@NCCGroupInfosec)

nccgroup.com/media/b2chcbti…

#infosec

Phillipp Eisenhower 已轉發

The Definitive Guide To Process Cloning on Windows huntandhackett.com/blog/the-defin… TLDR; This article aims to provide with a comprehensive technical details process cloning on Windows and how they affect its usability also explore why most techniques for code injection via cloning will…

5mukx's tweet image. The Definitive Guide To Process Cloning on Windows

huntandhackett.com/blog/the-defin…

TLDR; This article aims to provide with a comprehensive technical details process cloning on Windows and how they affect its usability also explore why most techniques for code injection via cloning will…

Phillipp Eisenhower 已轉發

Malware development tricks, by @cocomelonckz 46 Windows keylogger cocomelonc.github.io/malware/2025/0… 47 Windows clipboard hijacking cocomelonc.github.io/malware/2025/0… 48 leveraging Office macros cocomelonc.github.io/malware/2025/0… 49 abusing Azure DevOps REST API for covert data channels cocomelonc.github.io/malware/2025/0…


Phillipp Eisenhower 已轉發

Hollowing processes on Windows 11 Starting from 24H2 classic RunPE breaks due to changes in Windows loader logic. @hasherezade investigated the changes and proposed few alternative approaches to resolve the problem. Fantastic post, Ola! Post: hshrzd.wordpress.com/2025/01/27/pro… #redteam

SEKTOR7net's tweet image. Hollowing processes on Windows 11

Starting from 24H2 classic RunPE breaks due to changes in Windows loader logic. @hasherezade investigated the changes and proposed few alternative approaches to resolve the problem.

Fantastic post, Ola!

Post: hshrzd.wordpress.com/2025/01/27/pro…

#redteam…

Phillipp Eisenhower 已轉發

🧠 Master Network Packet Analysis with Wireshark Unlock the full potential of Wireshark the world’s leading network protocol analyzer and an essential tool for every cybersecurity professional. 📩 Comment “PDF” to get the full guide

_0b1d1's tweet image. 🧠 Master Network Packet Analysis with Wireshark

Unlock the full potential of Wireshark the world’s leading network protocol analyzer and an essential tool for every cybersecurity professional. 

📩 Comment “PDF” to get the full guide

Phillipp Eisenhower 已轉發

A pdb inspector I wrote a few years ago codeproject.com/articles/How-T…


Phillipp Eisenhower 已轉發

SSH Tunnels: Port Forwarding on steroids Yesterday, we talked about Port Forwarding - an old networking trick that makes an endpoint accessible via a different address. Ports can be forwarded with socat & netcat, but there is a much more powerful and ubiquitous alternative: SSH.

iximiuz's tweet image. SSH Tunnels: Port Forwarding on steroids

Yesterday, we talked about Port Forwarding - an old networking trick that makes an endpoint accessible via a different address. Ports can be forwarded with socat & netcat, but there is a much more powerful and ubiquitous alternative: SSH.

Phillipp Eisenhower 已轉發

Released my write for gaining a fundamental understanding of the Windows _SECURITY_DESCRIPTOR structure. I then created a custom Windows Kernel shellcode stub to perform process injection for privilege escalation which is also implemented in Sickle :P wetw0rk.github.io/posts/understa…

wetw0rk.github.io

Understanding the Windows _SECURITY_DESCRIPTOR

Understanding the Windows _SECURITY_DESCRIPTOR


Phillipp Eisenhower 已轉發

Large multilateral effort regarding DPRK Cyber Ops and the IT Work efforts. There is so much to unpack here and a lot of orgs/countries took a swing at it. Check it out and will post some pics for pizzazz. msmt.info/Publications/d…

aptwhatnow's tweet image. Large multilateral effort regarding DPRK Cyber Ops and the IT Work efforts. There is so much to unpack here and a lot of orgs/countries took a swing at it. Check it out and will post some pics for pizzazz.

msmt.info/Publications/d…

Phillipp Eisenhower 已轉發

Building LiveServe - a development server in C! You'll learn: • Hot reload via WebSocket • Real-time file monitoring • HTTP server with Mongoose • Event-driven architecture

_trish_xD's tweet image. Building LiveServe - a development server in C! 

You'll learn:
• Hot reload via WebSocket
• Real-time file monitoring  
• HTTP server with Mongoose
• Event-driven architecture

Phillipp Eisenhower 已轉發

Digging into Windows Defender Detection History (WDDH) orangecyberdefense.com/global/blog/cy…

5mukx's tweet image. Digging into Windows Defender Detection History (WDDH)

orangecyberdefense.com/global/blog/cy…

Phillipp Eisenhower 已轉發

🔒 Secure Bits 💡 𝗣𝗹𝗮𝗶𝗻𝘁𝗲𝘅𝘁 𝗣𝗮𝘀𝘀𝘄𝗼𝗿𝗱𝘀 𝗶𝗻 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝟭𝟭? 𝗦𝘁𝗶𝗹𝗹 𝗽𝗼𝘀𝘀𝗶𝗯𝗹𝗲. Modern Windows versions like Windows 11 and Windows Server 2025 are 𝗳𝗮𝗿 𝗺𝗼𝗿𝗲 𝘀𝗲𝗰𝘂𝗿𝗲 𝗯𝘆 𝗱𝗲𝗳𝗮𝘂𝗹𝘁. But 𝗹𝗲𝗴𝗮𝗰𝘆 𝗰𝗼𝗺𝗽𝗼𝗻𝗲𝗻𝘁𝘀 𝗰𝗮𝗻…

horizon_secured's tweet image. 🔒 Secure Bits 💡
𝗣𝗹𝗮𝗶𝗻𝘁𝗲𝘅𝘁 𝗣𝗮𝘀𝘀𝘄𝗼𝗿𝗱𝘀 𝗶𝗻 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝟭𝟭? 𝗦𝘁𝗶𝗹𝗹 𝗽𝗼𝘀𝘀𝗶𝗯𝗹𝗲.

Modern Windows versions like Windows 11 and Windows Server 2025 are 𝗳𝗮𝗿 𝗺𝗼𝗿𝗲 𝘀𝗲𝗰𝘂𝗿𝗲 𝗯𝘆 𝗱𝗲𝗳𝗮𝘂𝗹𝘁. But 𝗹𝗲𝗴𝗮𝗰𝘆 𝗰𝗼𝗺𝗽𝗼𝗻𝗲𝗻𝘁𝘀 𝗰𝗮𝗻…

Loading...

Something went wrong.


Something went wrong.