Golgothus (Zach)'s Avatar

Golgothus (Zach)

@golgothus

Senior Incident Response Engineer | Threat Hunting, IR, Cloud | ENFJ | http://wlo.link/@golgothus Your friendly CSO! (Chief Soap Officer) x.com/golgothus

64
Followers
79
Following
6
Posts
02.11.2024
Joined
Posts Following

Latest posts by Golgothus (Zach) @golgothus

Shell32.dll, #44 lolbin

www.hexacorn.com/blog/2025/05...

18.05.2025 00:51 ๐Ÿ‘ 5 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

LOL

This makes me think of when I tried installing FLARE on windows 11. You can still disable defender in GPO, but the installer doesn't see it, there's also web protection that breaks installs ๐Ÿฅฒ

19.11.2024 22:57 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Pretty stoked, finished one of the #DEATHCon2024 threat hunting challenges from a workshop to win swag.

It was a good opportunity to flex:
- initial access / exploitation
- execution
- persistence mechanisms
- exfiltration

While tinkering with SPL for results I needed.

19.11.2024 18:52 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
BRC4 Malware Analysis and Deobfuscation (Stream - 9/11/2024)
BRC4 Malware Analysis and Deobfuscation (Stream - 9/11/2024) YouTube video by Invoke RE

youtu.be/-X1n3BEfzv8?...

16.11.2024 12:46 ๐Ÿ‘ 49 ๐Ÿ” 12 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Windows Defender stopping / killing a powershell script to emulate APT29

Windows Defender stopping / killing a powershell script to emulate APT29

Me trying to have a good time running malware.

Windows Defender:
"How about, no."

16.11.2024 01:39 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Preview
Join DART What to know about becoming an infrastructure specialist on DART.

Have you ever considered being part of our team? Check out our article written by my colleague Tim about what our team does and what it's like to be part of the Microsoft incident response team. techcommunity.microsoft.com/blog/microso...

13.11.2024 20:30 ๐Ÿ‘ 12 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I've liked things so far

Reminds me of what Twitter used to be when it was actually good, but with some additional pieces

13.11.2024 22:52 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
michael jordan is wearing a suit and tie and says `` stop it '' . ALT: michael jordan is wearing a suit and tie and says `` stop it '' .

I've really enjoyed tinkering with my proxmox server. What's even better is now that I have a public facing web server proxied through Cloudflare I keep getting notifications of attacks on my network ๐Ÿฅฒ

11.11.2024 21:41 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Kasm Install | Golgothus' Lab

Wrote a brief post about Kasm web, really awesome tool to use for creating persistent as well as ephemeral containers

docs.golgothus.tech/other-resear...

Planning to try and use these for DEATHCON, thankfully I made sure to snapshot my VM before the install in case it broke ๐Ÿ˜…

07.11.2024 02:00 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0