Every once in a while, I get the urge to go back and revisit older techniques that used to be popular but have fallen out of favor with the offensive community. Things like Office Macros, PowerShell, and custom shellcode loaders used to be incredibly effective but are now deemed “burned” by many industry colleagues I chat with. While there is some truth to this, I am still constantly surprising myself and others on my team with so-called “burned” TTPs that prove themselves effective on operations.
In this post, I want to revisit another old technique I believe is a prime candidate to host malware payloads—Python for Windows. But, before we do, let’s revisit some existing work in this space. Operating Inside the Interpreted: Offensive Python
Notes

Genius is not insanity. Genius is having a clear head with an incredible ability to focus.

I’ve been reversing Black Ops Cold War for a while now, and I’ve finally decided to share my research regarding the user-mode anti-cheat inside the game. It’s not my intention to shame or promote cheating/bypassing of the anti-cheat, so I’ve redacted a few things. Reverse Engineering Call Of Duty Anti-Cheat
Call of Duty: Black Ops 3 is protected by a DRM that, among other things, protects the integrity of the game’s code at runtime. Reverse engineering those integrity checks has been a personal goal I had for a long time. In this post I’m going to describe my process of achieving exactly that, so let’s dive in. Reverse Engineering Integrity Checks in Black Ops 3
The biggest protection against piracy was to make the games not worth playing, let alone worth cracking.
This post is intended for educational purposes only. Denuvo is arguably the most successful digital rights management solution to have ever existed, and is therefore an interest to many. This blog contains a large amount of my personal notes and correspondence with other reverse engineers (see kudos) which contains information about the recent iterations of Denuvo, lots of which I haven’t seen shared publicly before.
Denuvo is an anti-tamper and digital rights management system (DRM). It is primarily used to protect digital media such as video games from piracy and reverse engineering efforts. Unlike traditional DRM systems, Denuvo employs a wide range of unique techniques and checks to confirm the integrity of both the game’s code and licensed user. Denuvo Analysis
She said, “It’s not now or never
Wait ten years, we’ll be together”
I said, “Better late than never
Just don’t make me wait forever”
Don’t make me wait forever.

“My Dinner with Andre” was recommended to me by a friend/visitor of my website, and what a recommendation this was! Beautiful film, evey bit as relevant now as when it was first released. Definitely one of the greatest films of all time, it’s that special kind that stimulates your own questioning and thinking. If you like those kind of movies, you’re in for a treat by watching Mindwalk, 1990, one of my favorite movies ever.
They’ve built their own prison, so they exist a state of schizophrenia. They’re both guards and prisoners and as a result they no longer have, having been lobotomized, the capacity to leave the prison they’ve made, or to even see it as a prison.
The world we live in is not a world that is kind to the dreamers, David Lynch himself fought tooth and nail to get to where he got and even then he wasn’t free to dream.
Why did nobody notice that Robbie Williams was a monkey the whole time?
Last week I posted an article about how the professional site Stack Overflow renamed the account of Luigi Mangione while keeping all of Luigi’s content under a different name (seemingly in violation of the Creative Commons license). The company has not commented officially. We know at one point my article made it to the front page listing because we have an archived copy. However, it mysteriously dropped off.
[…]
The reason why is a pretty open secret in the industry. It’s a tool frequently employed called shadow banning. Moderators have the option of using this tool whereby the ban isn’t made apparent to the user most likely to complain, in this case the submitter.
What Hacker News did was scrub the article from the front page to deny new exposure, and allow those that have seen it to engage as if nothing happened. They have a history of these kinds of shenanigans. Hacker News where the billionaires hack together your news
You are on a fight against an opponent you can’t see but oh you can feel on your heels can’t you? Feel him breathing down your neck. You know what that is? That’s you. Your fears, your doubts and insecurities, all ganged up like a firing squad ready to shoot you out of the sky. But don’t lose heart, while they are not easily defeated they are far from invincible. Remember, this is the grind, a battle royale between you and your mind, your body and the devil on your shoulders telling you this is just a game, this is just a waste of time, your opponents are stronger than you.
[…]
Luck is the last dying wish of those who wanna believe that winning can happen by accident. Sweat on the other hand is for the ones who know it’s a choice. So decide now, because destiny waits for no man.
So when the time comes and a thousand different voices are trying to tell you: you are not ready for it, listen instead to that lone voice of dissent, one that says you are ready, you are prepared, it’s all up to you, so rise and shine.
Night has always pushed up day
You must know life to see decay
But I won’t rot, I won’t rot
Not this mind and not this heart,
I won’t rot.

I’m fucking tired of getting older and everyone I care about dying.
→ in reply to @note#1737063831
Scratch that, reports are coming out that he isn’t actually confirmed dead, but that he disappeared in a bright flash of light presumably to return to his home planet.

RIP David Lynch, the last talented American. Gutted. A beautiful man in an dispassionate world.
Dark dream world
All alone
Shadows movin’
Shadows have long gone by
Shadows have long gone by
Dark night of the soul.




























