Vincent Yiu
  • Red Team
  • About Vincent Yiu
  • Red Team Tips
  • Videos
  • Red Team
    • Attack Infrastructure
      • CloudFlare for IP Address Filtering
      • Azure Apps for Command and Control
      • CobaltSplunk
    • Backdooring PE Files
      • Backdoor 101
      • Backdoor 102
      • Backdoor 103
    • Cloud Security
      • CloudFront Domain Hijacks under Attack
      • Vultr Domain Hijacking
      • CloudFlare for Command and Control
    • Command and Control
      • TryCloudFlare Infrastructure and Domain Fronting
      • Domain Fronting using StackPath CDN
      • HAMMERTHROW: Rotate my domain
      • Domain Fronting via. CloudFront Alternate Domains
      • Validated CloudFront SSL Domains
      • Domain Fronting: Who Am I?
      • Host Header Manipulation
      • Finding Target-relevant Domain Fronts
      • Alibaba CDN Domain Fronting
      • TOR Fronting — Utilising Hidden Services to Hide Attack Infrastructure
    • General Exploitation
      • Payload Generation with CACTUSTORCH
      • Exploiting CVE-2017–8759: SOAP WSDL Parser Code Injection
      • Exploiting CVE-2017–0199: HTA Handler Vulnerability
      • F# Shellcode Execution
      • Bypassing Gmail Attachment Virus Check
      • IPFuscation
    • Hardware and Gadgets
      • USBNinja
      • Aorus Gaming Box for Password Cracking
      • Proxmark Adventures 101
      • Poor man’s guide to Raspberry Pi initial installation
    • Post Exploitation
      • Introducing ANGRYPUPPY
      • RDPInception
      • VLAN Attacks
    • Reconaissance
      • Reconnaissance using LinkedInt
      • DomLink — Automating domain discovery
      • OffensiveSplunk vs. Grep
    • Misc
      • Under the wire: Trebek — Walkthrough
Powered by GitBook
On this page

Was this helpful?

Videos

PreviousRed Team TipsNextAttack Infrastructure

Last updated 6 years ago

Was this helpful?

This area contains a list of videos I've created on YouTube to help educate and inspire more cyber thinking!

USBNinja (Old name: USBHarpoon) - A BadUSB Cable Implementation

USBNinja - BT Edition Revealed

DomLink - Horizontal domain enumeration:

The Stageless LNK:

Alibaba CDN Domain Fronting:

CVE-2018-4878 Aggressor Script:

CVE-2018-4878 - SWF IE Driveby:

CVE-2017-8747 - SWF Exploit:

Fronting Through Asia - Alibaba CDN:

CVE-2017-8759 - Weaponisation Tutorial:

CVE-2017-8759 - RTF WSDL SOAP Parser Vulnerability 1-day:

MorphHTA:

Token Pivoting? High Integrity Level - SYSTEM -> TrustedInstaller:

ANGRYPUPPY - BloodHound Attack Automation in CobaltStrike:

BLUEBATTERY - Internet Explorer Enumeration and Manipulation:

LinkedInt - An automated LinkedIn scraper with e-mail format prediction:

CACTUSTORCH - CobaltStrike Aggressor Script:

CACTUSTORCH - DotNetToJScript all the things:

StarFighters - Run PowerShell without PowerShell within JS and VBS:

RDPInception - The Dangers of TSCLIENT:

TOR Fronting - Utilising Hidden Services for Privacy:

TOR Fronting - Utilising Hidden Services for Privacy:

Domain Fronting - Sophos Web Security Categorization:

Abusing Domain Fronting on Amazon CloudFront:

Paladins - EAC Bypass:

DPRK Malleable Profile (Just for lols):

Cobalt Strike CNA - Eventvwr UAC Bypass:

Office Template VDI Persistence:

Trusted Location Application Whitelist Bypass and Persistence for VDI:

WePWNise Introduction:

https://www.youtube.com/watch?v=6mDspyi5ROw
https://www.youtube.com/watch?v=UhBK-M2iXwA
https://www.bleepingcomputer.com/news/security/usbharpoon-is-a-badusb-attack-with-a-twist/
https://www.youtube.com/watch?v=iHlru5OyAbc
https://www.youtube.com/watch?v=7v21y21dleA
https://www.youtube.com/watch?v=01XwImjQYZs
https://www.youtube.com/watch?v=JhUlOIEdq0s
https://www.youtube.com/watch?v=erHQzMIRiq0
https://www.youtube.com/watch?v=IGIgI21HM4U
https://www.youtube.com/watch?v=IK-mJ-HmQJ8
https://www.youtube.com/watch?v=hlkx5uYBT1Y
https://www.youtube.com/watch?v=nHXKnTTtWk8
https://www.youtube.com/watch?v=X4S2aQ4o_jA
https://www.youtube.com/watch?v=ytZ22kvuhrQ
https://www.youtube.com/watch?v=yxQ8Q8itZao
https://www.youtube.com/watch?v=qlTXfZeaiVI
https://www.youtube.com/watch?v=7d-CAVhSHY0
https://www.youtube.com/watch?v=_pwH6a-6yAQ
https://www.youtube.com/watch?v=YiaKb8nHFSY
https://www.youtube.com/watch?v=axBf-4oxOds
https://www.youtube.com/watch?v=uLFBpdjrXx0
https://www.youtube.com/watch?v=OARw7yg0Ypc
https://www.youtube.com/watch?v=I3ovfrqcF0I
https://www.youtube.com/watch?v=0imkl8K4gvY
https://www.youtube.com/watch?v=zSBnM2HcRTw
https://www.youtube.com/watch?v=LYw6koxkIdw
https://www.youtube.com/watch?v=biodnXcvDvE
https://www.youtube.com/watch?v=ULIYnrPhgns
https://www.youtube.com/watch?v=Dkr2aBXpiM0
https://www.youtube.com/watch?v=gGQ_yxRtfI0
https://www.youtube.com/watch?v=trDr3cZRWSA