home.social

#winre — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #winre, aggregated by home.social.

  1. Can't trust a scan from within an infected OS. This snippet triggers Windows Defender Offline Scan via WinRE, booting into a minimal PE environment with updated signatures to catch persistent, hidden malware. Windows 10/11, Server 2016+. #windows #snippet #offline-scan #winre #ValtersIT

    valtersit.com/vault/offline-sc

  2. Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. winfuture.de/news,159633.html?

  3. Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. winfuture.de/news,159633.html?

  4. Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. winfuture.de/news,159633.html?

  5. Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. winfuture.de/news,159633.html?

  6. Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. winfuture.de/news,159633.html?

  7. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  8. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  9. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  10. *Kritische Sicherheitslücke in Windows-Systemen: BitLocker-Implementierungen gefährdet*
    In kürzester Zeit können Windows-11- und Windows-Server-Systeme mit BitLocker durch den Einsatz eines Proof of Concept (PoC) angreifbar gemacht werden.
    { #Szene #Windows #ITSicherheit #Windows11 #WinRE }
    >> nydus.org/news/135721-kritisch

  11. ----------------

    🎯 Threat Intelligence
    ===================

    Executive summary. A researcher published a reproduction for a BitLocker bypass originating from a WinRE component. The method requires copying a folder named FsTx to System Volume Information\FsTx on removable media or into the EFI area, then triggering a specific WinRE restart key sequence to obtain a shell with unrestricted access to the BitLocker‑protected volume. The report states the issue affects Windows 11 and Server 2022/2025; Windows 10 is not affected. The disclosure credits MORSE, MSTIC and Microsoft GHOST.

    🔹 Technical details

    • Affected images: Windows Recovery Environment (WinRE) on Windows 11 builds and Server 2022/2025 according to the author.

    • Trigger mechanism: copy FsTx folder to System Volume Information\FsTx on a USB stick or write equivalent files to the EFI partition. Boot the machine, invoke Restart → WinRE via holding SHIFT while clicking Restart, then release SHIFT and hold CTRL during the transition per the reproduction steps. The author reports that if performed correctly, a shell is spawned with access to the BitLocker volume.

    • Component presence: the author notes the responsible component appears only inside the WinRE image. The same component name exists in normal Windows installs but allegedly lacks the triggering functionality. The author characterizes this as suspicious but labels it preliminary.

    🔹 Analysis

    The observable elements are concrete: folder name FsTx, path System Volume Information\FsTx, WinRE entrypoint and the key sequence behavior. No CVE, vendor advisory, or formal patch is cited in the disclosure. The author speculates about intentional inclusion but explicitly calls the claim tentative. The source did not provide binary hashes, signed module names, or precise module APIs invoked.

    🔹 Detection

    The disclosure does not include vendor detection rules. Observable indicators from the report that defenders can log or hunt for include presence of an FsTx folder on removable media or unexpected files in the EFI partition, and unusual WinRE session activity following the described key sequence. No IoCs or hashes were published in the source.

    🔹 Mitigation

    The source did not publish mitigations or vendor guidance. Microsoft engagement is mentioned via credited teams, but no advisory is linked in the report. Until vendor guidance appears, administrators should treat the finding as preliminary.

    🔹 References

    Author disclosure credited MORSE, MSTIC and Microsoft GHOST. The report is labeled preliminary and the source does not verify intent or supply full technical artifacts.

    🔹 bitlocker #winre #windows11 #yellowkey #microsoft

    🔗 Source: github.com/Nightmare-Eclipse/Y