3Jun-25
Doppelganger: An Advanced LSASS Dumper with Process Cloning
Github Repo: https://github.com/vari-sh/RedTeamGrimoire/tree/main/DoppelgangerWhat is LSASS?
The Local Security Authority Subsystem Service (LSASS) is a core component of the Windows operating system, responsible for enforcing the security policy on the system. LSASS is a process that runs as lsass.exe and plays a fundamental role in: User authentication: It verifies users logging into the system, interacting with authentication protocols such as NTLM and Kerberos. Credential management: It...
29May-25
Exploring the LockBit Panel Breach – What Logs and Chats Reveal About Ransomware-as-a-Service
On May 7, 2025, a number of domains associated with the LockBit ransomware group were subjected to a web defacement attack by an unknown individual. Visitors to the compromised domains encountered the following message, replacing the original website content: Don’t do crime. CRIME IS BAD. xoxo from Prague On the same page, a file named “paneldb_dump.zip” was available for download. This archive...
28May-25
Behind The Scenes: Yarix Approach to Physical Security
TL;DR: In our experience, even organizations that you'd think are really solid often have serious gaps in their physical securitys—simply because they’ve never put their defenses to the test. And those that have invested heavily in technology frequently overlook the human factor, which remains one of the weakest links. In this post, we share a practical framework for building a physical...
17Apr-25