Security Researcher | Red Teamer | Malware Developer

Joined July 2020
9 Photos and videos
Mor Davidovich retweeted
21 Jun 2024
Elastic Security Labs has discovered a new method for initial access and evasion in the wild, termed #GrimResource, which involves arbitrary execution in mmc.exe through a crafted MSC file. elastic.co/security-labs/gri… gist.github.com/joe-desimone…
10
169
438
45,418
Mor Davidovich retweeted
Happy Solstice! Time to celebrate Truth and Justice. I appreciate your support; and I want to let you try one of my value-packed & expensive commercial masterclasses: ☀️ Masterclass: Hacking Fuzzers for Smarter Bughunting (on-demand video) zerodayengineering.com/train… This class will give you a core level grasp of modern evolutionary coverage-guided fuzzing as pro hackers use it. It goes fast from fuzzing essentials to advanced customization & examining how code coverage works on CPU assembly level, 4 hours hands-on video. Free access from 21st to 23rd June (access conditions below)

66
77
161
47,400
Mor Davidovich retweeted
16 Dec 2023
One Box To Rule Them All Little write up of my way to tackle remote pentesting situations with a dropbox. This is about non covert systems that will allow you to carry out full fledged pentests when implanted into the customers network. luemmelsec.github.io/One-Box…
1
30
100
10,236
16 Oct 2023
RT @Idov31: I usually tend to avoid politics but nowadays it is impossible. To all the Hamas supporters that reading this post, all the peo…
2
Mor Davidovich retweeted
Cashing in on browser behaviour to silently download executable files. A blog post by @defte_: sensepost.com/blog/2023/brow…
2
77
189
34,415
Mor Davidovich retweeted
The entire SCCM hierarchy is vulnerable to takeover from any primary site because by design, there is no security boundary between sites in the same hierarchy. Check out my new post to learn more about how this can be abused, mitigated, and detected! posts.specterops.io/sccm-hie…
3
128
290
29,895
Mor Davidovich retweeted
Our EXE loader is now available to everyone on GitHub: github.com/Maldev-Academy/Ma… We'll be uploading more repositories on our GitHub in the future.
1
116
434
42,124
20 Sep 2023
Love to see our work inspires stuff like that. Check out @sam_phisher new blog post on Automating MalRDP deployment with Terraform and Ansible. Great Work!
15 Sep 2023
I saw this the other day, and took a look at @ShorSecLtd's article. Brilliant work that I wanted to try to automate somewhat. My blog post about deploying MalRDP to Azure with Terraform and Ansible: skal.red/automating-malrdp-m…
3
811
Mor Davidovich retweeted
My Okta for Red Teamers post is up! We look at how Kerberos SSO works, how to intercept credentials via a fake AD Agent, decrypting AD Agent tokens, adding skeleton key's, and even how to deploy a janky SAML IdP server to auth as any user for good measure. trustedsec.com/blog/okta-for…
24
369
907
98,554
11 Sep 2023
New blog post of mine and my first in our "The Path to DA" series where I share a cool attack path I exploited in a recent engagement to gain Domain Admin privileges. Hope you like it :) shorsec.io/blog/the-path-to-…

🔥New Blog Post Alert! The next chapter in our "The Path to DA" series is now live: "(Relaying) To The Internet And Back". This entry, by @dec0ne, explores yet another route to DA, focusing on the intricacies of ADIDNS Abuse, LDAP relay, RBCD, and more. shorsec.io/blog/the-path-to-…
4
16
82
12,304
Mor Davidovich retweeted
6 Sep 2023
Part 5 of Lord Of The Ring0 is out! idov31.github.io/2023/07/19/… On this part, I explained how APC and thread injection made from the kernel to a user mode process, IRP & SSDT hook, why they don't work anymore (and their alternatives) #infosec #CyberSecurity

4
69
180
18,939
14 Aug 2023
Excited to share my new research: a POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local/remote processes. github.com/ShorSec/DllNotifi… An accompanying blog post with more details: shorsec.io/blog/dll-notifica…
We are excited to share a new "threadless" process injection technique by @dec0ne. This new technique utilizes DLL Notification Callbacks in the remote process to trigger the shellcode github.com/ShorSec/DllNotifi… Detailed blog post: shorsec.io/blog/dll-notifica… Demo video in next tweet
6
139
410
47,627
Mor Davidovich retweeted
Had the honor to present my research at @defcon 31 this year! Here is the link to the Github repo of the PoC tool I demonstrated: github.com/deepinstinct/Cont… Research abstract: forum.defcon.org/node/245719 A more detailed and technical blog post will be uploaded soon.
3
70
182
22,543
Mor Davidovich retweeted
SCCM Site takeover by abusing the AdminService API. In this blog, I walkthrough the discovery process and demonstrate site takeover via credential relaying. medium.com/specter-ops-posts…
4
145
292
35,543
Mor Davidovich retweeted
Wrote something on how to bypass Google Safe Browsing for Phishing campaigns🧐 r-tec.net/r-tec-blog-evade-s…
12
117
380
48,833
This is brilliant! Amazing work from @HamamOfir and @nm10pt 🔥🔥🔥
I'm thrilled to share that my latest blog co-written with @nm10pt is now live! 👉 Read the full blog post here: blog.sygnia.co/guarding-the-… I'd love to hear your thoughts and feedback on the post. Drop your comments below or share
3
659
First blog post in our upcoming series - "Path to DA" where Shlomi and I will be sharing our experiences, stories, strategies and techniques for achieving Domain Admin privileges on engagements. Mine is up next, stay tuned! shorsec.io/blog/the-path-to-…

🚀 Exciting news! We are launching our new blog series "The Path to DA"! where we will share our strategies for achieving Domain Admin on engagements our experiences, and stories. Our aim? Making complex topics easy and inspiring for all. Stay tuned! shorsec.io/blog/the-path-to-…
3
39
142
30,565