Lab52 is the threat intelligence division of S2 Grupo, an international cybersecurity company that offers its services around the world.
StopDefender. Stop Windows Defender programmatically
987LeakedHandlesFinder. Leaked Windows processes handles identification tool
298StealAllTokens. This PoC uses two diferent technics for stealing the primary token from all running processes, showing that is possible to impersonate and use whatever token present at any process
55Syspce. System Processes Correlation Engine
19SandboxIt. C++
10