Cyber Security Consultant | Security Researcher

And since it's an arbitrary file deletion, we can easily use it to exploit the MSI installer rollback to achieve privilege escalation :) github.com/ZeroMemoryEx/IObi…
Shoutout to the homies at "IObit Malware Fighter". Their IMFForceDelete driver is so wildly vulnerable, and poorly written, you can have their driver arbitrarily delete any file on the machine with 0 privileges and literally 1 line of code Thanks @_mmpte_software for sharing
5
78
328
33,424
Published a blog on my previous exploit. I've also discovered a privilege escalation vulnerability affecting MSI, Lenovo, ASUS, Alienware, Huawei laptops, and more. The vulnerability has been confirmed, stay tuned for the write-up once it's patched! hackandhide.com/from-dos-to-…
2
33
147
9,451
It’s been a while since I posted any updates here, so here’s a recap. I’ve fixed errors and memory leaks, improved error handling, added file restriction and integrity bypass features, and implemented a driver swap for disk and memory for more detail,check github.com/ZeroMemoryEx/Chao…
4
26
134
10,834
Anas retweeted
In this week’s red team tip. I will show how to use @ZeroMemoryEx AMSI Killer to patch AMSI and allow Invoke-Mimikatz to run. This attack does get detected by Windows Defender, but it’s too late as memory is already patched. #hacking #redteam piped.video/QFp3ybRKr7Q
1
6
1,919
Lazarus-Tactic: program based on APT38 North Korea-backed hackers tactic that used in targeting security researchers using a malicious Visual Studio project file (vcxproj) to steal their 0days. github.com/ZeroMemoryEx/APT3…
29
66
7,857
Just published new blog post tinyurl.com/4ua23wzv! How can you hook systemcalls in kernel on Windows 11 22H2, how does Avast Free Antivirus use it and how you can bypass Avast’s self-defense in 10 lines of PowerShell code right now? All answers are provided in the article
3
114
264
it can be very annoying for analysts to wait for the malware to do its true malicious behavior,That's why i made this program that patch the Sleep function and speed up the execution ,check it out. github.com/ZeroMemoryEx/Slee… #malwareanalysis #cybersecurity #malwaredetection #redteam
2
27
72
The world of Ransomware is full of surprises: LockBit allegedly paid out their first “bug bounty” to someone who highlighted decryption flaws in the LB3 ESXi variant. The flaw made it possible to bypass having to pay the ransom for a key
15
185
602
Anas retweeted
Presenting D-Generate , syscall tracing as its supposed to be! raw.githubusercontent.com/jo… usage: dg cmd.exe - displays all syscalls done by process with cmd.exe as imagefile. dg 4736 - by pid 4736 dg - just everything example of recording: raw.githubusercontent.com/jo…
17
236
795
Arbitrary read/write -> arbitrary kernel-mode API calls with HVCI and Kernel CFG enabled :) - in this case a POC to invoke ZwOpenProcess on the System process in VTL 0. I will blog on this soon!
7
75
325
Anas retweeted
DirectX
4
6
184
Unable to extract credentials via DPAPI or Mimikatz? Don't worry. Microsoft got your back. Just use 'rundll32 keymgr.dll, KRShowKeyMgr' to extract all the stored passwords on the host, be it a target server, FTP or chrome's HTTP creds, microsoft has you covered. #redteam
48
796
2,639