Interacting with Users
Traffic Capture

Tools
Monitoring for Process Command Lines
Vulnerable Services
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
https://research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild/research.checkpoint.com
SCF on a File Share
ntlm_theft
CME
Rocabella
LNK File on a File Share
lnkdomb
Netexec


Rocabella
URL Files on a File Share
Obfuscated Files
Interesting Book
Interesting BooksSupport this Gitbook
Last updated


