I'm releasing a crude POC Melkor. Melkor DPAPI encrypts .Net assemblies in memory and can decrypt & execute them on demand in a new AppDomain. This technique is an adaptation of a TTP used by InvisiMole. More details here --> github.com/FuzzySecurity/Sha…
DC29 BTV Volunteer Signups open up in a few weeks! Join our discord and follow the village twitter for future updates! Volunteers are #1 as without them we are not a team!
#blueteamvillage#btv#dc29#defcon29#defcon@defcon
BlueTeamVillage Discord:
discord.gg/8nrkRNa
Updates for Process Monitor (v3.82), TCPView (v4.12), Process Explorer (v16.42) and Sysmon (v13.21) have now been posted!
Get the tools at sysinternals.com
See what's new on the Sysinternals Blog: techcommunity.microsoft.com/…
We have confirmation; BTV's call for content is now -extended- to May 30th!
So come on in and submit at cfc.blueteamvillage.org/call… - we're looking forward to seeing what you come up with this year!
Good News, Everyone! #DEFCON29 pre-reg is open at shop.defcon.org! Reserve a spot in Vegas or get your ticket for #DC29online. Thank you for your support and patience as we navigate this crazy year - August 5 can't come soon enough! Let's DO this!
DEF CON ❤️ U.
We have confirmation; BTV's call for content is now -extended- to May 30th!
So come on in and submit at cfc.blueteamvillage.org/call… - we're looking forward to seeing what you come up with this year!