- SignalDesk1小时前
Original Summary
Hey everyone, I engineered ProxSuite PRO (Apex v2.5), a standalone ~95 KB zero-dependency native x64 Windows live memory forensics and endpoint security command center uniting 25 engines: * EvasionHunter: Detects Module Stomping (
.textRAM vs. Disk comparison), Process Ghosting, Herpaderping, and Unbacked Thread Call-Stacks. * MemGuard & HollowHunter: Audits liventdll.dllsyscall prologues (4C 8B D1 B8) and scansMEM_PRIVATERWX regions for unbacked PE headers. * LSASS Deep Shield: Audits LSA Security Packages for SSP injection and detectsPssCaptureSnapshot/comsvcs.dlldump activity. * NamedPipe C2 & RAM Scanner: Hunts Cobalt Strike, Sliver, Havoc, and Brute Ratel named pipes plus live LOLBIN memory indicators. * Self-Defense & SIEM: Kernel DACL anti-terminate protection,FILE_SHARE_READbinary lock, dynamicprox_rules.jsonrules, and SIEM webhook streaming. GitHub Repository & Interactive Web Simulator: https://github.com/prox0959/ProxSuite-PRO Would love feedback on the architecture and interactive simulator!   submitted by   /u/Traditional_Bear5492 [link]   [comments]- 情报分类:服务器与云资源
- 分类依据:内容涉及服务器、云资源或网络线路
- 信息来源:Reddit · SideProject
- 发布时间:2026/9/28 05:55:41
- 暂无回复