-CyberSecurityTechnologies-


Kanal geosi va tili: Belarus, Inglizcha


Welcome to -CyberSecurityTechnologies- Channel:
- BlueTeam (APT/OpSec/DFIR)
- OffSec (RedTeaming/TH/Pentesting)
- Reversing/Malware Analisys (TTPs)
- Web Security/DevSecOps
- AI Security/MLSecOps
- Tools/PoC/Research
Tags: t.me/CyberSecurityTechnologies/2

Связанные каналы  |  Похожие каналы

Kanal geosi va tili
Belarus, Inglizcha
Statistika
Postlar filtri


HijackRAG.pdf
661.2Kb
#MLSecOps
"HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models", 2024.


#Kernel_Security
Kernel Callback Tables for Process Injection
https://github.com/0xHossam/KernelCallbackTable-Injection-PoC


eNVMe.pdf
6.3Mb
#Research
#Hardware_Security
"Pandora’s Box in Your SSD: The Untold Dangers of NVMe", 2024.
]-> https://github.com/rick-heig/eNVMe




#tools
#Threat_Research
CVE2CAPEC - Get CVE, CWE, CAPEC, MITRE ATT&CK Techniques data automatically
https://github.com/Galeax/CVE2CAPEC


Sneaking_around_WASM.pdf
2.5Mb
#WebApp_Security
"Sneaking around with Web Assembly", 2024.




Evil_MSI.pdf
3.8Mb
#Whitepaper
"Evil MSI. A story about vulnerabilities in MSI Files", 2024.




ML_Security.pdf
10.1Mb
#Tech_book
"Machine Learning Security Principles:
Keep data, networks, users, and applications safe from prying eyes", 2022.


jdd.pdf
474.2Kb
#Research
"Efficient Detection of Java Deserialization Gadget Chains via Bottom-up GadgetSearch and Dataflow-aided Payload Construction", 2024.


#exploit
1. CVE-2024-46483:
Pre-Auth Heap Overflow in Xlight SFTP server
https://github.com/kn32/cve-2024-46483

2. CVE-2024-38812:
VMWare vCenter Server DCERPC
https://blog.sonicwall.com/en-us/2024/10/vmware-vcenter-server-cve-2024-38812-dcerpc-vulnerability

3. CVE-2024-6473:
Yandex Browser




Ransomware_Protect_Strategies.pdf
4.2Mb
#hardening
#Whitepaper
"Ransomware Protection and Containment Strategies Guide: Practical Guidance for Hardening and Protecting Infrastructure, Identities and Endpoints", 2024.


#OpSec
1. LoadLibrary madness: dynamically load WinHTTP.dll
https://www.riskinsight-wavestone.com/en/2024/10/loadlibrary-madness-dynamically-load-winhttp-dll
2. NukeAMSI - tool to neutralize the Antimalware Scan Interface (AMSI) in Windows environments
https://github.com/anonymous300502/Nuke-AMSI


Mitre_Attacks_Det_2.pdf
2.7Mb
#Blue_Team_Techniques
"MITRE Attacks Detection Rules:
The MITRE ATT&CK Alerts For log point", Part 2, 2023.

]-> Part 1


#Sec_code_review
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code
https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html


#exploit
1. CVE-2024-27954:
WP Automatic Plugin - Path Traversal/SSRF
https://github.com/Quantum-Hacker/CVE-2024-27954

2. CyberPanel v2.3.6 pre-auth RCE
https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce

3. RCE Vulnerability in QBittorrent
https://sharpsec.run/rce-vulnerability-in-qbittorrent


5G_TLS_vulns.pdf
2.2Mb
#cryptography
#5G_Network_Security
"Analysing open-source 5G core networks for TLS vulnerabilities and 3GPP compliance", 2023.

]-> framework for analyzing TLS libraries:
https://github.com/tls-attacker/TLS-Attacker



20 ta oxirgi post ko‘rsatilgan.