Kyle Cucci(@d4rksystem) 's Twitter Profile Photo

hunting tip of the week:

by hasherezade can oftentimes extract CS implants and loader shellcode directly from memory (depending, of course, on code injection methods). Try this out during investigations into suspect processes!

#CobaltStrike hunting tip of the week:

#PEsieve by @hasherezade can oftentimes extract CS implants and loader shellcode directly from memory (depending, of course, on code injection methods). Try this out during investigations into suspect processes!
account_circle
hasherezade(@hasherezade) 's Twitter Profile Photo

New / (v0.3.9): github.com/hasherezade/pe… & github.com/hasherezade/ho… - now you can search for your own signatures in memory. Details: github.com/hasherezade/pe…. Check it out!

New #PEsieve/#HollowsHunter (v0.3.9): github.com/hasherezade/pe… & github.com/hasherezade/ho… - now you can search for your own signatures in memory. Details: github.com/hasherezade/pe….  Check it out!
account_circle
hasherezade(@hasherezade) 's Twitter Profile Photo

New / (v0.3.5): github.com/hasherezade/pe… & github.com/hasherezade/ho… - with some bugfixes & improvements. Check it out!

New #PEsieve/#HollowsHunter (v0.3.5): github.com/hasherezade/pe… & github.com/hasherezade/ho… - with some bugfixes & improvements. Check it out!
account_circle
SECURITY CASE STUDY(@SCSconference) 's Twitter Profile Photo

We're excited to introduce hasherezade will be a Speaker at . She will sharing of knowledge about tool this year’s edition taking place on 13-14 September 2018, Warsaw, Poland.

We're excited to introduce @hasherezade will be a Speaker at #SCSconference. She will sharing of knowledge about #PEsieve tool this year’s edition taking place on 13-14 September 2018, Warsaw, Poland.
account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

AVG AntiVirus doesn't hook that many APIs. This doesn't make me feel safe 🤮

-Hooks functions invocations via SetWindowsHookEx (No App_Init presence), loads aswhook.dll
-Flags as malware 😭
-List of *some hooked APIs: pastebin.com/khu8DkUM

🤔

AVG AntiVirus doesn't hook that many APIs. This doesn't make me feel safe 🤮

-Hooks functions invocations via SetWindowsHookEx (No App_Init presence), loads aswhook.dll 
-Flags #PEsieve as malware 😭
-List of *some hooked APIs: pastebin.com/khu8DkUM

🤔
account_circle
hasherezade(@hasherezade) 's Twitter Profile Photo

In the meanwhile in / : refactored to use a new sig_finder (github.com/hasherezade/si…) , which gives an improved performance, and ability to load signatures with wildcards. Soon you will be able to add your own signatures for memory scans 🙂

In the meanwhile in #PEsieve/#HollowsHunter: refactored to use a new sig_finder (github.com/hasherezade/si…) , which gives an improved performance, and ability to load signatures with wildcards. Soon you will be able to add your own signatures for memory scans 🙂
account_circle
waldoirc(@waldoirc) 's Twitter Profile Photo

Since releasing malmemdetect and providing a list of IOCs i feel more comfortable releasing this. github.com/waldo-irc/YouM…

This is a project implementation of x64 gargoyle and sRDI to bypass PeSieve and Moneta in memory as threads. It’s stable, blog post after shmoo.

account_circle
ringzerø.training && @ringzer0@infosec.exchange(@_ringzer0) 's Twitter Profile Photo

📢 New Release Alert!

0.2.6 - bit.ly/pesieve
v0.2.6 - bit.ly/hollowshunter

New releases now support scanning for !

Wanna learn Analysis? Check out hasherezade at 🔥 bit.ly/ringzero-windo…

📢 New Release Alert!

#PEsieve 0.2.6 - bit.ly/pesieve
#HollowsHunter v0.2.6 - bit.ly/hollowshunter

New releases now support scanning for #IAT #hooks!

Wanna learn #Windows #Malware Analysis? Check out @hasherezade at #Ringzer0 🔥 bit.ly/ringzero-windo…
account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

New LOKI v0.27.0
> changed log format in TEXT and SYSLOG output to allow you the collection and analysis of LOKI logs in THOR APT Scanner's Splunk App
> PESieve check skipped on WinXP
github.com/Neo23x0/Loki/r…

New LOKI v0.27.0
> changed log format in TEXT and SYSLOG output to allow you the collection and analysis of LOKI logs in @thor_scanner's @splunk App 
> PESieve check skipped on WinXP
github.com/Neo23x0/Loki/r…
account_circle
Laszlo Kokai(@kokail) 's Twitter Profile Photo

RT hasherezade: The last (github.com/hasherezade/pe…) and (github.com/hasherezade/ho…) this year! (v0.2.4) - some improvements & many important fixes, so please don't miss it.

RT @hasherezade: The last #PEsieve (github.com/hasherezade/pe…) and #HollowsHunter (github.com/hasherezade/ho…) this year! (v0.2.4) - some improvements & many important fixes, so please don't miss it.
account_circle
Jane(@GSDjane) 's Twitter Profile Photo

Boris Johnson you allowed promoted using outside. I and many suffering ? I know you pesieve social housin residents as rubbish. Sick disabled autistic end of life live steps from hell Druid st beer mile 47 licensed hell holes l😢drunks been assaulted knock ? businesses awful

account_circle