
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Defend ] Short post on my PowerShell talk @ BSidesCharm w/ overview, slides, & some info on PS Remoting. Slides updated. https://adsecurity.org/?p=2843
" PowerShell 安全之企业如何防御最新攻击平台的攻击: https://t.co/4vOSS1cvoX"
-
[ Detect ] Great series of blog posts on using Sysmon: http://securitylogsanalysis.blogspot.com/
" 基于 Splunk 的终端日志分析和威胁检测: http://securitylogsanalysis.blogspot.com/2016/04/analysis-of-endpoint-logs-with-splunk.html 基于 Sysmon 的威胁检测: http://securitylogsanalysis.blogspot.com/2016/04/sysmon-playbook-v1.html "
-
[ Detect ] Great BSides presentation by @ markpars0ns on hunting threats by pivoting off of TLS certs: http://mpars0ns.github.io/bsidescharm-2016slides/ #DFIR
"基于 TLS 证书信息的威胁检测, 来自 Bsides 会议,在线 Slides: https://t.co/FB6LQYO73Y "
-
[ Hardware ] Building a portable GSM BTS using Nuand BladeRF, Raspberry Pi and YatesBTS step by step tutorial - https://blog.strcpy.info/2016/04/21/building-a-portable-gsm-bts-using-bladerf-raspberry-and-yatebts-the-definitive-guide/
"用 Nuand BladeRF、树莓派、YatesBTS 一步步搭建一个便携式 GSM 基站: https://t.co/eUfrDW9DMQ"
-
[ iOS ] The slides from my @ BSidesROC iOS talk are now online. Enjoy, and thanks to all who came to see the talk! https://twitter.com/NullBits/status/723928258853523457
"iOS 的加密体系,包括全盘加密、Passcode 等,来自 BSides 会议的演讲: https://t.co/xkg6R8jBNX"
-
[ Linux ] Foreign LINUX - Linux system call interface emulator for the Windows platform - a` la WSL - https://github.com/wishstudio/flinux
"FLinux - 运行在 Windows 系统的 Linux 二进制翻译器、系统调用模拟器,使得在 Windows 系统可以直接运行未修改的 Linux 二进制程序: https://t.co/zTDpiH1qZh"
-
[ ReverseEngineering ] Solving kao's toy project with symbolic execution and angr http://0xec.blogspot.com.by/2016/04/solving-kaos-toy-project-with-symbolic.html
"用符号执行方法以及 angr 框架破解 Kao Toy CrackMe: https://t.co/XVnfOQcicC "
-
[ ThreatIntelligence ] This is a great list of threat intel resources http://www.cyintanalysis.com/resources/
" 威胁情报资源收集: https://t.co/BjmNNYs7We 其中有一个 Github 项目整理了一个列表: https://github.com/hslatman/awesome-threat-intelligence "
-
[ Tools ] Finally rewrote #EliDecode http://developpsoft.github.io//EliDecode/ Cc: #infosec #obfuscated @ github @ unicorn_engine @ capstone_engine #indiedev
" EliDecode - 混淆后 Shellcode 的解码工具,基于 Capstone 反汇编引擎: https://t.co/wcLaYw7bPq "
-
[ Tools ] NRS is a set of Python librairies used to unpack and analysis NSIS installer's data. Based on IDAPython. https://github.com/isra17/nrs
"NRS - NSIS 安装程序解析和分析工具,基于 IDAPython: https://t.co/UVmXYb47CB"