<?xml
version="1.0" encoding="utf-8"?>
<rss version="2.0" 
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
>

<channel xml:lang="en">
	<title> Sevagas</title>
	<link>https://blog.sevagas.com/</link>
	<description>This site is about IT security. Here we present the authors articles and security tools. This site is cooperative, feel free to comment and criticize any article/application. If you want to publish your articles and/or applications on this site, send a request to contact[at]sevagas.com.</description>
	<language>en</language>
	<generator>SPIP - www.spip.net</generator>

	<image>
		<title> Sevagas</title>
		<url>https://blog.sevagas.com/IMG/logo/logo-test_mockup_transp.png?1695579982</url>
		<link>https://blog.sevagas.com/</link>
		<height>60</height>
		<width>144</width>
	</image>


	
	 
	 
	 
	 
  	
  	 
  	
	

	



<item xml:lang="en">
		<title>RedTeam With OneNote</title>
		<link>https://blog.sevagas.com/?RedTeam-With-OneNote</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?RedTeam-With-OneNote</guid>
		<dc:date>2022-08-09T15:07:32Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;OneNote is one of the Office suite components which is often overlooked when RedTeaming. Though OneNote cannot execute VBA Macros, it has an important potential for phishing as an initial vector.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-MacroPack-" rel="directory"&gt;MacroPack&lt;/a&gt;


		</description>



		
		<enclosure url="https://blog.sevagas.com/IMG/pdf/redteam_with_onenote.pdf" length="590128" type="application/pdf" />
		

	</item>
<item xml:lang="en">
		<title>RedTeam With Publisher</title>
		<link>https://blog.sevagas.com/?RedTeam-With-Publisher</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?RedTeam-With-Publisher</guid>
		<dc:date>2022-04-28T16:22:31Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;Microsoft Publisher is another tool of the Office suite which is often ignored when RedTeaming. This is a basic review of the great potential Publisher has for Offensive Security engagements.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-MacroPack-" rel="directory"&gt;MacroPack&lt;/a&gt;


		</description>



		
		<enclosure url="https://blog.sevagas.com/IMG/pdf/redteam_with_publisher.pdf" length="638409" type="application/pdf" />
		

	</item>
<item xml:lang="en">
		<title>MSDT DLL Hijack UAC bypass</title>
		<link>https://blog.sevagas.com/?MSDT-DLL-Hijack-UAC-bypass</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?MSDT-DLL-Hijack-UAC-bypass</guid>
		<dc:date>2022-02-02T15:23:54Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;UAC Bypass via DLL hijacking of Microsoft Support Diagnostic Tool (MSDT). The UAC bypass method described here is based on DLL hijacking which happens when loading the Bluetooth diagnostic package.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-Windows-" rel="directory"&gt;Windows&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>Hide HTA window for RedTeam</title>
		<link>https://blog.sevagas.com/?Hide-HTA-window-for-RedTeam</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Hide-HTA-window-for-RedTeam</guid>
		<dc:date>2021-07-15T18:14:19Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;Short post to explain how to create a stealthy HTA file running without any window or taskbar mention. This can be used combined withe other techniques to create advanced payloads for redteaming/supply chain attacks.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-Windows-" rel="directory"&gt;Windows&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>Launch shellcodes and bypass Antivirus using MacroPack Pro VBA payloads</title>
		<link>https://blog.sevagas.com/?Launch-shellcodes-and-bypass-Antivirus-using-MacroPack-Pro-VBA-payloads</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Launch-shellcodes-and-bypass-Antivirus-using-MacroPack-Pro-VBA-payloads</guid>
		<dc:date>2021-01-21T18:11:52Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;If you have ever been frustrated with manually writing Office/VBS payloads that ends up being detected by antivirus read this post!&lt;br class='autobr' /&gt;
&lt;a href=&#034;https://github.com/sevagas/macro_pack&#034; class=&#034;spip_out&#034; rel=&#034;external&#034;&gt;MacroPack&lt;/a&gt; Pro provides multiple options and templates related to shellcode launch, these options enable to build VBA code which is not detected by most security solutions. &lt;br class='autobr' /&gt;
Let me show you how MacroPack Pro automatically generates Office, HTA, shortcut, etc. shellcode launcher payloads which bypass security solutions.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-MacroPack-" rel="directory"&gt;MacroPack&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>Advanced MacroPack payloads: XLM Injection </title>
		<link>https://blog.sevagas.com/?Advanced-MacroPack-payloads-XLM-Injection</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Advanced-MacroPack-payloads-XLM-Injection</guid>
		<dc:date>2020-09-18T16:28:06Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;How it is possible to inject and run Excel 4.0 macro in memory from a non Excel format payload (ex Word, HTA, Help files,...). How to generate using MacroPack Pro.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-MacroPack-" rel="directory"&gt;MacroPack&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>EXCEL 4.0 XLM macro in MacroPack Pro</title>
		<link>https://blog.sevagas.com/?EXCEL-4-0-XLM-macro-in-MacroPack-Pro</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?EXCEL-4-0-XLM-macro-in-MacroPack-Pro</guid>
		<dc:date>2020-09-18T16:26:56Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;Excel 4.0 macro (also called XLM) have been commonly used by malicious operators these last years, it has also been analyzed and commented by several researches (red or blue). So I decided to add the support of this language for MacroPack Pro.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-MacroPack-" rel="directory"&gt;MacroPack&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>Code Injection - Weaponize GhostWriting Injection</title>
		<link>https://blog.sevagas.com/?Code-Injection-Weaponize-GhostWriting-Injection</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Code-Injection-Weaponize-GhostWriting-Injection</guid>
		<dc:date>2020-09-02T16:24:08Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;Lets talk about this code injection technique called GhostWriting that works by manipulating the register states of the target process thread.&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-Code-injection-series-" rel="directory"&gt;Code injection series&lt;/a&gt;


		</description>



		
		<enclosure url="https://blog.sevagas.com/IMG/pdf/code_injection_series_part5.pdf" length="389915" type="application/pdf" />
		

	</item>
<item xml:lang="en">
		<title>Bypass Defender and other thoughts on Unicode RTLO attacks </title>
		<link>https://blog.sevagas.com/?Bypass-Defender-and-other-thoughts-on-Unicode-RTLO-attacks</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Bypass-Defender-and-other-thoughts-on-Unicode-RTLO-attacks</guid>
		<dc:date>2020-05-25T19:00:19Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;I have been looking a bit into Unicode and Right-To-Left-Override phishing attacks lately. Mainly because I noticed that Windows Defender was detecting payloads generated with the &#034;&#8212;unicode-rtlo&#034; options of MacroPack...&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-Miscellaneous-" rel="directory"&gt;Miscellaneous&lt;/a&gt;


		</description>



		

	</item>
<item xml:lang="en">
		<title>Code Injection - Disable Dynamic Code Mitigation (ACG)</title>
		<link>https://blog.sevagas.com/?Code-Injection-Disable-Dynamic-Code-Mitigation-ACG</link>
		<guid isPermaLink="true">https://blog.sevagas.com/?Code-Injection-Disable-Dynamic-Code-Mitigation-ACG</guid>
		<dc:date>2019-12-01T21:00:05Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Emeric Nasi</dc:creator>







		<description>&lt;p&gt;How to disable Dynamic Code Mitigation Policy (ACG) to be able to inject code and deploy hooks into Microsoft Edge and others&lt;/p&gt;

-
&lt;a href="https://blog.sevagas.com/?-Code-injection-series-" rel="directory"&gt;Code injection series&lt;/a&gt;


		</description>



		
		<enclosure url="https://blog.sevagas.com/IMG/pdf/code_injection_series_part4.pdf" length="423195" type="application/pdf" />
		

	</item>



</channel>

</rss>