5 Followers
100 Following
121 Posts

Just a random guy in the internet that does ethical hacking for a living.

Red Team Lead

Twitterhttps://twitter.com/LeonVQZz
Websitewhoami.leonvqz.com
VolunteerRaicesCyberOrg
Faculty@thetaggartinstitute

I played @blackhillsinfosec backdoors and breaches, this was the story (kinda crazy):

We're a MSP, our client got attacked with ransomware, let's investigate.

After some Firewall Log Review, we found out they're exfiltrating data using the BITS protocol.

Looking through the SIEM Logs, we see some activity of credential stuffing using found valid AD credentials on open shares.

Then we get a call from the head of security that the incident was from a current pentest from other consulting company.

We kept investigating to practice our blue team skills, let's go threat hunting! with this we got to know that with Social Engineering an user was deceived to run malware on its computer.

Boooo! We find all our data posted in pastebin 💀

Now the we need Persistence vector after knowing the Initial Compromise, Pivot & Escalate, and C2 & Exfil vectors. We decided to go the basics and use SANS IR cheatsheets to discover backdoors on the systems and with this we discover that the attackers hijacked the order in which DLLs are loaded

it was fun! @ATHL337 @hax0r77 @cybermunchkiin

Hey everyone! Today is giving Tuesday!!! Help @RaicesCyberOrg fund our activities like the latest Raices Sec+ Cohort with the teachers @_bad_delta and @christophelimp, that just finished yesterday (with one certified student and more to come when they take the exam)

https://bank.hackclub.com/donations/start/raices-cyber-org

If you have any questions about Raíces feel free to ask me anything!

Donate to Raices Cyber Org

Donate to Raices Cyber Org. Your contribution will be tax-deductible.

Hack Club Bank