Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Red Team Level over 9000!

Автор: MiSecGroup

Загружено: 2019-06-14

Просмотров: 190

Описание:

**Our apologies but the first 20 minutes has no audio due to the mic input being off. :'(

Red Team Level over 9000! Fusing the powah of .NET with a scripting language of your choosing: introducing BYOI (Bring Your own Interpreter) payloads.

Speaker: Marcello Salvati

“Offensive PowerShell tradecraft is in “Zombie Mode”: it’s sorta dead, but not entirely. With all of the defenses Microsoft has implemented in the PowerShell runtime over the past few years Red Teamers / Pentesters & APT groups have started too shy away from using PowerShell based payloads/delivery mechanisms and migrate over to C#. However, C# is a compiled language, operationally this has a few major downsides: we can’t be as “flexible”, setting up a proper development environment has overhead and can be time consuming, you have to compile all the things all the time etc.. Bottom line is I’m lazy and creating your malwarez/custom payloads in C# is not as easy & straight forward as it would be in PowerShell or really any scripting language.

This raises the following quandary: can we somehow get our own scripting language interpreter on the target machine while still remaining opsec safe and use it to perform all of our post-exploitation activities?

Turns out by harnessing the sheer craziness of the .NET framework, you can embed entire interpreters inside of .NET languages allowing you to natively execute scripts written in third-party languages (like Python) on windows! Not only does this allow you to dynamically access all of the .NET API from a scripting language of your choosing, but it also allows you to still remain completely in memory and has a number of advantages over traditional C# payloads! Essentially, BYOI payloads allow you to have all the “power” of PowerShell, without going through PowerShell in anyway!

In this talk we will be covering some key .NET framework concepts in order to understand why this is possible, how to actually do the interpreter/engine/runtime embedding, the concept (that I coined) “engine inception”, differences between traditional C# payloads & BYOI payloads, demoing some examples of BYOI payloads and finally SILENTTRINITY: an open-source C2 framework that I’ve written that attempts to weaponize some of the BYOI concepts.”

May 17 @ 13:10
110 pm - 200 pm 50'
Track 1

Red Team Level over 9000!

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

array(10) { [0]=> object(stdClass)#6030 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "KFFPuSbgHHo" ["related_video_title"]=> string(45) "Decomposing Risk: What does a Blue Team Stop?" ["posted_time"]=> string(19) "6 лет назад" ["channelName"]=> string(10) "MiSecGroup" } [1]=> object(stdClass)#6003 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "FqG-9vKhGtg" ["related_video_title"]=> string(42) "C# is better than you think | Prime Reacts" ["posted_time"]=> string(19) "1 год назад" ["channelName"]=> string(12) "ThePrimeTime" } [2]=> object(stdClass)#6028 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "iBNplaTyc_k" ["related_video_title"]=> string(27) "Command and Control in 2020" ["posted_time"]=> string(63) "Трансляция закончилась 5 лет назад" ["channelName"]=> string(10) "MiSecGroup" } [3]=> object(stdClass)#6035 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "HPSnQapJxQg" ["related_video_title"]=> string(57) "Арест Z-блогера (English subtitles) @Max_Katz" ["posted_time"]=> string(23) "7 часов назад" ["channelName"]=> string(19) "Максим Кац" } [4]=> object(stdClass)#6014 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "1P25vG16cuk" ["related_video_title"]=> string(52) "251. What Microsoft Choosing Go over C# Can Teach Us" ["posted_time"]=> string(25) "2 месяца назад" ["channelName"]=> string(11) "IAmTimCorey" } [5]=> object(stdClass)#6032 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "jipybKSCvJk" ["related_video_title"]=> string(114) "Чем занимается С# разработчик? Специализации и преимущества С#" ["posted_time"]=> string(21) "4 года назад" ["channelName"]=> string(18) "Sergey Nemchinskiy" } [6]=> object(stdClass)#6027 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "uUrpicDpiWs" ["related_video_title"]=> string(100) "Покушение на Зеленского / Предатель в Офисе президента" ["posted_time"]=> string(24) "13 часов назад" ["channelName"]=> string(10) "NEXTA Live" } [7]=> object(stdClass)#6037 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "192KLouTZMA" ["related_video_title"]=> string(90) "Игра, опередившая время на десятилетия | The Movies 2005" ["posted_time"]=> string(21) "1 день назад" ["channelName"]=> string(7) "Amytrip" } [8]=> object(stdClass)#6013 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "8j5YBZ-c2uU" ["related_video_title"]=> string(57) "Что выбрать в 2022 году: C# или Python?" ["posted_time"]=> string(21) "3 года назад" ["channelName"]=> string(18) "Sergey Nemchinskiy" } [9]=> object(stdClass)#6031 (5) { ["video_id"]=> int(9999999) ["related_video_id"]=> string(11) "eRk5phHX4U8" ["related_video_title"]=> string(72) "#misec Southfield/OWASP Oakland County - Cloudy with a chance of Malware" ["posted_time"]=> string(65) "Трансляция закончилась 4 года назад" ["channelName"]=> string(10) "MiSecGroup" } }
Decomposing Risk: What does a Blue Team Stop?

Decomposing Risk: What does a Blue Team Stop?

C# is better than you think | Prime Reacts

C# is better than you think | Prime Reacts

Command and Control in 2020

Command and Control in 2020

Арест Z-блогера (English subtitles) @Max_Katz

Арест Z-блогера (English subtitles) @Max_Katz

251. What Microsoft Choosing Go over C# Can Teach Us

251. What Microsoft Choosing Go over C# Can Teach Us

Чем занимается С# разработчик? Специализации и преимущества С#

Чем занимается С# разработчик? Специализации и преимущества С#

Покушение на Зеленского / Предатель в Офисе президента

Покушение на Зеленского / Предатель в Офисе президента

Игра, опередившая время на десятилетия  | The Movies 2005

Игра, опередившая время на десятилетия | The Movies 2005

Что выбрать в 2022 году: C# или Python?

Что выбрать в 2022 году: C# или Python?

#misec Southfield/OWASP Oakland County - Cloudy with a chance of Malware

#misec Southfield/OWASP Oakland County - Cloudy with a chance of Malware

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]