Git Product home page Git Product logo

malware_learns's Introduction

This repo wil be a dumping ground of stuff I have learnt/am learning

Trying to focus on AV evasion, payloads have been covered in SLAE

Have completed https://www.pentesteracademy.com/course?id=3
Have completed https://www.pentesteracademy.com/course?id=50
Have completed https://institute.sektor7.net/view/courses/red-team-operator-malware-development-essentials/
Have completed https://www.pentesteracademy.com/course?id=37

Will need to do x64 SLAE at some point: https://www.pentesteracademy.com/course?id=7

Time to do OSEP, after that likely CRTO, definitely advanced malware by sektor7, then cybernetics/APT prolab

To read and digest:
https://makosecblog.com/malware-dev/dll-unhooking-csharp/
https://klezvirus.github.io/RedTeaming/AV_Evasion/CodeExeNewDotNet/
https://www.mdsec.co.uk/2020/03/hiding-your-net-etw/
https://0xpat.github.io/Malware_development_part_1/
https://stackoverflow.com/questions/48969793/how-to-load-dll-dynamically-and-pass-get-value-to-it
https://stackoverflow.com/questions/9905237/older-code-cant-get-a-handle-on-a-dll
https://stackoverflow.com/questions/14479074/c-sharp-reflection-load-assembly-and-invoke-a-method-if-it-exists
https://thewover.github.io/Dynamic-Invoke/
https://posts.specterops.io/offensive-p-invoke-leveraging-the-win32-api-from-managed-code-7eef4fdef16d
https://ethicalchaos.dev/2022/04/17/in-process-patchless-amsi-bypass/
https://waawaa.github.io/es/amsi_bypass-hooking-NtCreateSection/ - To do: implement and test against EDR
https://www.ired.team/offensive-security/code-injection-process-injection/reflective-shellcode-dll-injection

Tools to study:
https://www.netero1010-securitylab.com/evasion/indirect-syscall-in-csharp?fbclid=IwAR3pMyp01GGUNVrlbLlsfIaBITrNLlej2KZmC_3LS5aefSSVADbHPrYswoU. https://github.com/klezVirus/SysWhispers3 (super important)
https://github.com/TheWover/DInvoke
https://github.com/jthuraisamy/SysWhispers2
https://github.com/paranoidninja/CarbonCopy
https://github.com/TheWover/donut
https://github.com/kyleavery/AceLdr
https://github.com/boku7/BokuLoader

Resources: https://malapi.io/

Resources:
http://pinvoke.net/default.aspx/Structures.IMAGE_DOS_HEADER //will need this for building manual maps

malware_learns's People

Contributors

fengjixuchui avatar kymb0 avatar

Stargazers

 avatar  avatar

Forkers

alehacksp

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.