netbiosX

@netbiosx.bsky.social

Purple Team

🎙️ Threat actors with elevated permissions could register a fake AMSI provider to establish persistence. 𝑫𝒆𝒕𝒆𝒄𝒕𝒊𝒐𝒏 𝑺𝒕𝒓𝒂𝒕𝒆𝒈𝒊𝒆𝒔 ✅️ 7 - Sysmon Fake AMSI Provider DLL ✅️ 4663 - Modification of HKLM\SOFTWARE\Microsoft\AMSI\Providers Registry Key ✅️ 4688 - regsvr32 Process ✒️ ipurple.team/2026/07/13/a...

AMSI Provider

The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However,…

ipurple.team

📢 QoS Policies - Restrict EDR agents Traffic from generating telemetry & Detection Strategies 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐒𝐭𝐫𝐚𝐭𝐞𝐠𝐲 - 𝐄𝐯𝐞𝐧𝐭 𝐈𝐃𝐬 ✅️️️ 5857 - CIM Provider ✅️️️ 4104 - PowerShell ScriptBlock ✅️️️ 4663 - Registry Key Modification ✅️️️ 4688 - Process Creation ✅️️️ qoswmi.dll 🖊️ ipurple.team/2026/06/17/q...

QoS Policies

In Windows, a Quality of Service (QoS) policy is a rule that handles outbound network traffic. Specifically, it is used to cap the outbound bandwidth of a process, port, or protocol. Organizations …

ipurple.team

🎙️ EntryPoint Hijacking introduces a stealthier approach to code injection. 🛠️ 𝐀 𝐍𝐞𝐰 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧‑𝐂𝐚𝐩𝐚𝐛𝐢𝐥𝐢𝐭𝐲 is introduced that monitors: 🧠 The memory address of the EntryPoint 🧬 Changes to the EntryPoint memory type 🛑 OriginalBase validity ✒️ 𝐑𝐞𝐚𝐝 𝐭𝐡𝐞 𝐟𝐮𝐥𝐥 𝐚𝐫𝐭𝐢𝐜𝐥𝐞 ipurple.team/2026/05/13/e...

EntryPoint Hijacking

The technique of EntryPoint Hijacking introduces a stealthier approach to code injection as it doesn’t use API calls that create a new thread within the context of a process, and it independe…

ipurple.team