2Oct-25
Red Teaming & Jazz: Creativity as a Service
Red Teaming & Jazz: Creativity as a Service Foreword I had been missing on this blog for a bit and I told myself it was time to go back to writing something. If in the previous article (here is the link) I wanted to make a sort of small professional contribution to the sector, in this case it is a further customization...
16Sep-25
Elons (Proxima/Black Shadow related) ransomware attack via Oracle DBS External Jobs
Premise As Yarix’s Incident Response Team, our responsibilities are to manage critical issues related to cyber-attacks carried out by cybercriminals, intervening promptly in order to guarantee security to victim companies and to minimize latent risks, analyzing the systems within their infrastructures and indicating precise remediation actions capable of re-establishing a state of security sufficient for normal operational recovery. In the course of...
3Jun-25
Doppelganger: An Advanced LSASS Dumper with Process Cloning
Github Repo: https://github.com/vari-sh/RedTeamGrimoire/tree/main/Doppelganger What is LSASS? The Local Security Authority Subsystem Service (LSASS) is a core component of the Windows operating system, responsible for enforcing the security policy on the system. LSASS is a process that runs as lsass.exe and plays a fundamental role in: User authentication: It verifies users logging into the system, interacting with authentication protocols such as NTLM and Kerberos. Credential management: It handles...
29May-25