Aggregator
全球视野 | 国际网安快讯(第31期)
LayeredSyscall – Abusing Vectored Exception Handling to Bypass EDRs
LayeredSyscall Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows. The general idea is to generate a legitimate call stack before...
The post LayeredSyscall – Abusing Vectored Exception Handling to Bypass EDRs appeared first on Penetration Testing Tools.
倒计时9天!2024补天白帽大会全议程发布!
Remote Method Guesser: Java RMI enumeration and bruteforce of remote methods
Remote Method Guesser Remote Method Guesser (rmg) is a command-line utility written in Java and can be used to identify security vulnerabilities on Java RMI endpoints. Currently, the following operations are supported: List available bound names and their...
The post Remote Method Guesser: Java RMI enumeration and bruteforce of remote methods appeared first on Penetration Testing Tools.
高通修复已遭利用的高危0day漏洞
Apache Avro SDK 中存在严重漏洞,可导致在 Java 应用中实现RCE
HybridTestFramewrok: End to End automation testing of Web, API and Security
HybridTestFramewrok In the era of the cloud-native world, we cannot stick to a particular framework, however, due to project requirements we often need to evolve the existing testing solution in such a way that...
The post HybridTestFramewrok: End to End automation testing of Web, API and Security appeared first on Penetration Testing Tools.