Carlo Alberto Scola (@carloa_scola) 's Twitter Profile
Carlo Alberto Scola

@carloa_scola

Penetration Tester and Red Teamer.
Passionate of Web app and network security!
Snowboard addicted! Biker and DIY guy!

ID: 778514729220370433

linkhttps://carloalbertoscola.it calendar_today21-09-2016 08:42:30

123 Tweet

146 Followers

468 Following

Will Schroeder (@harmj0y) 's Twitter Profile Photo

In case you missed it, Charlie Clark and Andrew just released some _awesome_ work that just landed into Rubeus' master branch- "Diamond Tickets"! Check out more details at semperis.com/blog/a-diamond…. Great work Charlie and Andrew!!

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

Having fun learning how to build basic blocks of malware to evade EDRs! Today was just about process injection using the less documented NTAPI Just started my journey, but a step at a time. #edr #evasion #injection #malware lnkd.in/eTyp9Z-c

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

Basic tip 1 for cleanup: when you inject a DLL, you must remember to correctly unload it after you're done (FreeLibraryAndExitThread to the rescue), otherwise it will stay there forever after your threads are gone. Double check if you use generated dll if…lnkd.in/ev9t2bre

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

Sunday mornings be like: let's start designing a simple ICS honeypot! For sure current ICS honeypots need a bit of refresh though. #ics #honeypot #cybersecurity #industrial #control #system lnkd.in/esxdRmmz

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

I wanted to play around with the Process Hollowing for a while. Process hollowing is a well known and neat technique to mask your malicious code behind legit processes. Although, instead of rewriting the PE image I learned how to hijack the main thread o…lnkd.in/erWYkXZn

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

Learning about another type of TLS Callback today. Using Thread Local Storage callbacks to inject code into processes allows the execution of malicious code to happen way before the main entrypoint. Debuggers do not immediately see those. TLS callback are…lnkd.in/dsDhJ9uZ

Carlo Alberto Scola (@carloa_scola) 's Twitter Profile Photo

SEC-T Red-Blue team Truesec village. Come here and try hands on hacking into an environment or threat hunt your way to find what the attackers are doing! #cybersecurity lnkd.in/d7rFuFYq

Truesec (@truesec) 's Twitter Profile Photo

Modern IT environments offer passwordless authentication to improve security. Certificate and key-based authentication makes the user's life easier and gives the offensive side an excellent opportunity to obtain versatile credentials Hasain Alshakarti Carlo Alberto Scola at #secsummit

Modern IT environments offer passwordless authentication to improve security. Certificate and key-based authentication makes the user's life easier and gives the offensive side an excellent opportunity to obtain versatile credentials <a href="/Alshakarti/">Hasain Alshakarti</a> <a href="/carloa_scola/">Carlo Alberto Scola</a> at #secsummit
mgeeky | Mariusz Banach (@mariuszbit) 's Twitter Profile Photo

And just like that - 2 years long efforts of writing Initial Access and VBA macros generation framework tossed into dumpster, cause ChatGPT comes free of charge😆