Original Summary

Hey everyone, I engineered ProxSuite PRO (Apex v2.5), a standalone ~95 KB zero-dependency native x64 Windows live memory forensics and endpoint security command center uniting 25 engines: * EvasionHunter: Detects Module Stomping (.text RAM vs. Disk comparison), Process Ghosting, Herpaderping, and Unbacked Thread Call-Stacks. * MemGuard & HollowHunter: Audits live ntdll.dll syscall prologues (4C 8B D1 B8) and scans MEM_PRIVATE RWX regions for unbacked PE headers. * LSASS Deep Shield: Audits LSA Security Packages for SSP injection and detects PssCaptureSnapshot / comsvcs.dll dump activity. * NamedPipe C2 & RAM Scanner: Hunts Cobalt Strike, Sliver, Havoc, and Brute Ratel named pipes plus live LOLBIN memory indicators. * Self-Defense & SIEM: Kernel DACL anti-terminate protection, FILE_SHARE_READ binary lock, dynamic prox_rules.json rules, and SIEM webhook streaming. GitHub Repository & Interactive Web Simulator: https://github.com/prox0959/ProxSuite-PRO Would love feedback on the architecture and interactive simulator!   submitted by   /u/Traditional_Bear5492 [link]   [comments]


  • 情报分类:服务器与云资源
  • 分类依据:内容涉及服务器、云资源或网络线路
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/9/28 05:55:41