jack chou
@jackchou51706
Senior Technical Consultant @ISSDUTW
ID: 1662128382
11-08-2013 09:51:17
5,5K Tweet
919 Followers
4,4K Following
[#HackTip ⚒️] One idea for NTDS on-site dumping without VSS: NTFSCopy (thx Red Cursor) + #impacket’s RemoteOperations.getBootKey() + secretsdump[.]py (e.g., via a pre-compiled binary or Diego Capriotti’s awesome Pyramid) 🤪 ppn.snovvcrash.rocks/pentest/infras…
ReflectiveNtdll A Dropper POC focusing EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by hasherezade). Payload encryption via SystemFucntion033 NtApi and No new thread via Fiber github.com/reveng007/Refl… #redteam