Johan
@syndikalist
Mostly RT interesting stuff.
RT != Endorsement and all that jazz.
#WeAreNAFO
ID: 43728125
31-05-2009 18:17:14
16,16K Tweet
373 Followers
688 Following
Detecting Process Hollowing. A post by Leo Bastidas from TrustedSec exploring the popular technique, where a malicious payload is concealed within a legitimate process, and providing detailed methods for its detection and defense. Source: trustedsec.com/blog/the-night… #redteam
Alright here's another interesting one. More infostealer stuff but worth a look. There's a couple parts to this so I'll attempt to summarize. Thanks MalwareHunterTeam for sharing :) Starting with the initial mach-O, (readable strings?!?!) Ugly plist for persistence. 🧵