-
Detection CVE-2024-35250
Detects when cmd.exe with system privileges is executed after a process loads 'ksproxy.ax' and 'ksuser.dll', indicating potential exploitation of CVE-2024-35250.
-
APTs or UAPs?
How Anomalous Phenomena Are Similar to Cyber Threats.
-
Step-by-step Apache Guacamole Installation.
Guacamole Instalation
-
Script for enabling Windows Audit and Sysmon.
Windows audit and Sysmon
-
FnStegoCrypt - Encrypted Data in Images
A program that encrypts data using AES-GCM and embeds it into images with LSB.
-
Exposing Local Applications with FNLocalCloud.
An agent-server based program to expose local network services on the internet, bypassing CGNAT.
-
FIRST Fortaleza 2023.
FIRST (Forum of Incident Response and Security Teams)
-
CyberDefenders Qradar101 Write up.
Ctf Writeup