Log inSign up
Samir
2,841 posts
Image
user avatar
Samir
@SBousseaden
security @Elastic Mastodon: @[email protected]
Joined January 2013
1,162
Following
25.4K
Followers
  • Pinned
    user avatar
    Samir
    @SBousseaden
    Mar 28, 2024
    New blog post is up, exploring detection options for some recent In- the- Wild Windows LPE 0- days elastic.co/security-labs/…
    Image
    Image
    54K
  • user avatar
    Samir
    @SBousseaden
    Nov 15, 2019
    #threathunting mindmap to help getting familiar with some of windows core processes (whish I can add more but its already crowded)
    Image
  • user avatar
    Samir
    @SBousseaden
    Aug 1, 2019
    #redteam quick tip: if you want to execute stuff via WMI (local/remote) without bringing much attention, stage your scripts, payloads etc. in c:\windows\ccmcache\<number>\ folder and you will be fine, below a live legit exec on my laptop (and I see this a lot in # env)
    Image
  • user avatar
    Samir
    @SBousseaden
    May 6, 2021
    want to bypass Startup folder file write monitoring ? 1) rename "Startup" folder 2) drop the target file in the renamed startup folder 3) rename it back to "Startup"
    Image
  • user avatar
    Samir
    @SBousseaden
    Oct 24, 2019
    Hunting with Windows Security EventID 5145 summarized in one mindmap #threathunting 4648, 4624 are next
    Image
  • user avatar
    Samir
    @SBousseaden
    Feb 11, 2021
    nice trick to avoid suspicious powershell command line
    Image
    Image
  • user avatar
    Samir
    @SBousseaden
    Sep 26, 2019
    #redteam tunning tip: if you plan to drop a dll and load directly via macro from within office (winword or excel), use the following path %localappdata%\assembly\tmp\<rand>\a.b.c.dll (it's a busy tmp folder and I doubt EDRs will notify on every file creation in that folder)
    Image
  • user avatar
    Samir
    @SBousseaden
    May 8, 2022
    opening a pwd protected zip file using Windows Explorer generate a credman event 5379 with Target "Microsoft_Windows_Shell_ZipFolder:filename=zip_fil_path".
    Image
  • user avatar
    Samir
    @SBousseaden
    Apr 23, 2020
    started as a a fun way to take notes ... 16 mindmaps so far :) github.com/sbousseaden/Sl…
    Image
    Image
    Image
    Image
  • user avatar
    Samir
    @SBousseaden
    Nov 5, 2019
    a starting point #threathunting mindmap for Windows Services
    Image
  • user avatar
    Samir
    @SBousseaden
    Jul 13, 2020
    high likely its already out there, a cool backdoor opsec feature is to embeds a VT free API key and checks (once a day) for its hash if more than x matches automatic uninstall
    Image
  • user avatar
    Samir
    @SBousseaden
    Mar 6, 2020
    just a little mindmap summarizing this great write-up of several ways that can be used to elevate privs from sensitive-priv to system: github.com/hatRiot/token-…
    Image
  • user avatar
    Samir
    @SBousseaden
    Aug 22, 2020
    most difficult thing to learn in infosec is focus on one thing (including resisting unplanned/unexpected things you encounter while working on that one thing) :D
  • user avatar
    Samir
    @SBousseaden
    Jun 21, 2024
    Elastic Security Labs has discovered a new method for initial access and evasion in the wild, termed #GrimResource, which involves arbitrary execution in mmc.exe through a crafted MSC file. elastic.co/security-labs/… gist.github.com/joe-desimone/2…
    Image
    00:00
    45K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement