Joshua Penny(@josh_penny) 's Twitter Profile Photo

Interestingly, all servers, either hosting the first stage PDF in AWS/Azure, or the obfuscated PowerShell scripts, present a 302 redirect to the Microsoft homepage, however, what makes it unique and searchable is the '/?' suffix.

Interestingly, all #Horabot servers, either hosting the first stage PDF in AWS/Azure, or the obfuscated PowerShell scripts, present a 302 redirect to the Microsoft homepage, however, what makes it unique and searchable is the '/?' suffix.
account_circle
I_Am_Jakoby(@I_Am_Jakoby) 's Twitter Profile Photo

Powershell tips to make you a ✨Terrible✨
😈hacker and person👼

not gonna lie, having a little more fun than I should making these

p.s. if you are going to defcon join my discord and get the 💀Defcon💀 role so we can all coordinate together
discord.gg/iamjakoby

Powershell tips to make you a ✨Terrible✨
😈hacker and person👼

not gonna lie, having a little more fun than I should making these

p.s. if you are going to defcon join my discord and get the 💀Defcon💀 role so we can all coordinate together
discord.gg/iamjakoby
account_circle
Aaron Parker(@stealthpuppy) 's Twitter Profile Photo

Here's a set of PowerShell scripts that you can use to migrate an tenant from an existing set of Microsoft Store for Business apps to the new Microsoft Store apps with the same assignments AND icons! github.com/aaronparker/in…

Here's a set of PowerShell scripts that you can use to migrate an #Intune tenant from an existing set of Microsoft Store for Business apps to the new Microsoft Store apps with the same assignments AND icons! github.com/aaronparker/in…
account_circle
Gary Blok [GARYTOWN.COM](@gwblok) 's Twitter Profile Photo

Blog Post: Scheduled Tasks &
garytown.com/scheduled-task…

I've learned a few tricks recently I didn't want to forget.

This post covers the basics of making a task which runs a script from GitHub directly with event & time triggers.

Blog Post: Scheduled Tasks & #PowerShell
garytown.com/scheduled-task…

I've learned a few tricks recently I didn't want to forget.

This post covers the basics of making a task which runs a script from GitHub directly with event & time triggers. #Intune #ConfigMgr #Sysadmin
account_circle
Samir(@SBousseaden) 's Twitter Profile Photo

sample using DLL sideloading (calc.exe + urlmon.dll) def609f052deed96390ee9c6df217665 uses PPID spoof to launch powershell to downl payload from discord_cdn, even if parent pid spoofing (fake parent as explorer.exe) is used one can still see the src of the call in the stack trace

sample using DLL sideloading (calc.exe + urlmon.dll) def609f052deed96390ee9c6df217665 uses PPID spoof to launch powershell to downl payload from discord_cdn, even if parent pid spoofing (fake parent as explorer.exe) is used one can still see the src of the call in the stack trace
account_circle
Friedrich Weinmann(@FredWeinmann) 's Twitter Profile Photo

Heya people,
I just finished a new module for dealing with the most annoying part of coding: Documentation.
github.com/PowershellFram…
Using Azure to generate CBH - and insert it right into my function code:
dir -Recurse -Filter *.ps1 | Add-PsmdOaiFunctionHelp

account_circle
TOMO(@tomozh) 's Twitter Profile Photo

amazon.co.jp/gp/video/detai…
ハッキングのシーンでPowershell使ってるの初めて見たw

amazon.co.jp/gp/video/detai…
ハッキングのシーンでPowershell使ってるの初めて見たw
account_circle
eversinc33(@eversinc33) 's Twitter Profile Photo

Dumbest AMSI bypass I know so far, but it works: sideloading a fake amsi.dll to a copied version of powershell which simply return S_OK / AMSI_RESULT_CLEAN for every command. I would have thought that there was some kind of signature check upon loading amsi.dll but apparently not

Dumbest AMSI bypass I know so far, but it works: sideloading a fake amsi.dll to a copied version of powershell which simply return S_OK / AMSI_RESULT_CLEAN for every command. I would have thought that there was some kind of signature check upon loading amsi.dll but apparently not
account_circle
Linux Handbook(@LinuxHandbook) 's Twitter Profile Photo

Bash is not the only shell in Linux 🐧

Here are some more 👇

→ C Shell (csh)
→ Korn Shell (ksh)
→ Z Shell (zsh)
→ Fish Shell (fish)

I still prefer bash though.

Which one is your favorite shell?

account_circle