Maxime Thiebaut
@0xthiebaut
308 Permanent Redirect Location: infosec.exchange/@0xThiebaut 🇧🇪🕊🇺🇦
ID: 1084878647943675904
https://thiebaut.dev 14-01-2019 18:23:20
92 Tweet
694 Followers
147 Following
A few weeks ago Microsoft released #CVE_2022_41120, a “Microsoft Windows #Sysmon Elevation of Privilege Vulnerability” reported by Filip Dragovic . With the #vulnerability and original #PoC released, I can now share the first time I #diff'ed a patch. thiebaut.dev/articles/diffi…
🔎 IcedID’s VNC Backdoors: Dark Cat, Anubis & Keyhole A summary of #VNC #backdoor capabilities Maxime Thiebaut reconstructed from network traffic. 👀 Screenshots, videos and clipboard data at blog.nviso.eu/2023/03/20/ice… #Malware #PCAP #Reversing
MalwareHunterTeam Shadow Chaser Group Jazi maybe that someone was Maxime Thiebaut
JAMESWT_MHT Awesome article, and here is the tool that came with it put together by Maxime Thiebaut: github.com/0xThiebaut/PCA… Works like a charm; I used it more than once 🙂
From ScreenConnect to Hive Ransomware in 61 hours ➡️Initial Access: ScreenConnect ➡️Defense Evasion: BITS Jobs, Embedded Payloads ➡️Lateral Movement: Impacket, RDP, SMB ➡️C2: ScreenConnect, Atera, Splashtop, Cobalt Strike, Metasploit ➡️Exfil: Rclone thedfirreport.com/2023/09/25/fro… 1/X
New blog post! Title: MEGAsync Forensics and Intrusion Attribution | By Maxime Thiebaut (Maxime Thiebaut) Link: wp.me/p84lDr-4FS #Forensics #MEGAsync #LockBit #Python #Statecache
New blog post! Title: Hunting Chromium Notifications | By Maxime Thiebaut (Maxime Thiebaut) Link: wp.me/p84lDr-4sj #ThreatHunting #Phishing #Chromium #Chrome #Edge #Forensics