Bobby Cooke (@0xboku) 's Twitter Profile
Bobby Cooke

@0xboku

Adversary Services @ IBM X-Force Red

ID: 1236693035632623617

linkhttps://0xBoku.com calendar_today08-03-2020 16:39:47

3,3K Tweet

10,10K Takipçi

1,1K Takip Edilen

~synawk~ (@synaw_k) 's Twitter Profile Photo

Simple ways to obfuscate PEB retrieval instructions in order to avoid the gs+0x60/fs+0x30 synawk.com/blog/peb-obfus… #malware #redteam #windows

b33f | 🇺🇦✊ (@fuzzysec) 's Twitter Profile Photo

If you are using SAP NetWeaver I would apply the patch asap. Also, I strongly recommend you go and investigate manually because exploitation has been going on for a while.

Chris Spehn (@conscioushacker) 's Twitter Profile Photo

I hit level 60 in Classic Hardcore WoW to remind myself. What's old is new again. Never stop learning, never stop grinding. #RedTeamTip

I hit level 60 in Classic Hardcore WoW to remind myself. What's old is new again. Never stop learning, never stop grinding. #RedTeamTip
hasherezade (@hasherezade) 's Twitter Profile Photo

Cool beginner-level introduction to the PE format: youtube.com/watch?v=f1J07O… - featuring #PEbear 🐻: youtube.com/watch?v=f1J07O…

Cool beginner-level introduction to the PE format: youtube.com/watch?v=f1J07O… - featuring #PEbear 🐻: youtube.com/watch?v=f1J07O…
Logan Goins (@_logangoins) 's Twitter Profile Photo

I jumped heavily into learning about SCCM tradecraft and wrote a detailed write-up with custom examples, covering the most interesting vulnerabilities that combine commonality and impact from low-privilege contexts, and what you can do to prevent them :) logan-goins.com/2025-04-25-scc…

b33f | 🇺🇦✊ (@fuzzysec) 's Twitter Profile Photo

I'm reposting my IBM blog dealing with Lazarus and "Direct kernel object manipulation (DKOM) attacks on ETW providers" on knifecoat 🔪🧥 knifecoat.com/Posts/Direct+K…

I'm reposting my IBM blog dealing with Lazarus and "Direct kernel object manipulation (DKOM) attacks on ETW providers" on knifecoat 🔪🧥

knifecoat.com/Posts/Direct+K…
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Dennis Kniep This is a very neat trick! In my opinion clearly a vulnerability though, it shouldn't be possible to skip the first step this way. I imagine Microsoft will want to fix this, or was this reported and deemed as not a vuln?

MalDev Academy (@maldevacademy) 's Twitter Profile Photo

New update released! - Introduction to Keylogging - Developing a Keylogger - Sending Keystrokes To Remote Server - Manipulating VEH For Local Code Execution Shout out to 5pider and Mannyfreddy for their help in this update. More information: maldevacademy.com/syllabus

quarkslab (@quarkslab) 's Twitter Profile Photo

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Atsika's article on how it came to exist after an assumed breach mission ⤵️ 👉 blog.quarkslab.com/proxyblobing-i…

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure.
Check out <a href="/_atsika/">Atsika</a>'s article on how it came to exist after an assumed breach mission ⤵️
👉 blog.quarkslab.com/proxyblobing-i…
Atsika (@_atsika) 's Twitter Profile Photo

ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒 🌐 github.com/quarkslab/prox… Blog post for more details right below ⬇️

Steve Borosh (@rvrsh3ll) 's Twitter Profile Photo

In-case you missed the webcast, here's the GitHub link github.com/rvrsh3ll/Bolth…. Blog post coming soon! One of my fav bits we talked about was using this to have your C2 call to 127.0.0.1:port or even adding dev tunnels to the ClickOnce. Many options. Modify to taste 🧑‍🍳

Bobby Cooke (@0xboku) 's Twitter Profile Photo

🧙‍♂️Loki project is up to 25 vulnerable ⚡️Electron apps! What features would you like to see added to Loki? Private beta has: 🧦SOCKS5 proxy 📝Task Queue 🛜C2 Server ⚡️Agent rewrite 🥷Evasion github.com/boku7/Loki

Bobby Cooke (@0xboku) 's Twitter Profile Photo

BOF execution coming soon to Loki C2! Just got TrustedSec's COFFLoader working inside of a Node.js node module, callable from JavaScript! COFFLoader Project: github.com/trustedsec/COF… Loki C2 Project: github.com/boku7/Loki

BOF execution coming soon to Loki C2! Just got <a href="/TrustedSec/">TrustedSec</a>'s COFFLoader working inside of a Node.js node module, callable from JavaScript!

COFFLoader Project: github.com/trustedsec/COF…

Loki C2 Project: github.com/boku7/Loki