3 ms·
Maldev academy is slightly related. I always like to give a shout out to opensecuritytraining as well. In my experience, open source material like this is too
by _8j50 2y ago
Maldev academy is slightly related. I always like to give a shout out to opensecuritytraining as well.
In my experience, open source material like this is too Linux focused. But even with paid courses (doing one of them right now actually) bypassing exploit mitigations and protections is a topic that's hard to find materials on.
Egg hunting, module stomping topics like that with process mitigations turned on and modern edr/ngav running now that I'd pay good money for. In reality, I am trying to drink from the firehose and stumbling around github, customizing poc code and learning that way.
It's really hard to stand a chance at memory exploitation with good edrs and mitigations flipped on.
Another topic that's very important to me is arm exploitation. Azeria labs has good material on it, I haven't finished it to comment on it but there isn't as much material on arm as there is on x86.
You'll also notice most introductory material skips x64 but I'd be interested in x64 intensive material as well. For example, I've learned SEH exploitation multiple times now but it doesn't apply to x64, is it worth the time spent on it? How frequently do you see seh enabled x86 apps these days (genuine question)?
- 0xEF 2y agoLike you, I have noticed this type of material to be always Linux focused as well and wondered why. I'd love to see something like an Over The Wire security challenge game that is based on Windows or manOS if anyone knows of them.
- _8j50 2y agoI think it might be because microsoft charges money for windows licenses and you can't keep it free of charge and pay for licenses for the lab vms. But for exploit labs,you just need to give learners the samples and/or something like an ansible playbook to setup the vm and they can run it on their own box.
- chaosharmonic 2y agoI haven't gotten to this myself, but there's also UnderTheWire[0], which focuses on PowerShell. [0] https://underthewire.tech https://underthewire.tech