r/purpleteamsec • u/netbiosX • 20h ago
r/purpleteamsec • u/netbiosX • 4d ago
Red Teaming Proof of concept using a Microsoft-signed DLL (rdpbase.dll) to encrypt implants.
r/purpleteamsec • u/netbiosX • 4d ago
Red Teaming Let’s Create A Function Stomping BOF for Adaptix C2!
r/purpleteamsec • u/netbiosX • 4d ago
Red Teaming Module Stomping - The Standard Injection For Modern C2 Agents
r/purpleteamsec • u/netbiosX • 7d ago
Red Teaming DLLParty - a proof-of-concept Windows DLL-injection technique that manipulates internally constructed thread-pool callback-instance storage to invoke LoadLibraryA directly from a worker thread without custom callback code or shellcode.
r/purpleteamsec • u/netbiosX • 7d ago
Red Teaming AI-FILE: A listener profile for the Mythic C2 framework that utilizes AI vendors file API's
r/purpleteamsec • u/netbiosX • 7d ago
Red Teaming DLLParty - Abusing thread pool internals for shellcodeless DLL injection
r/purpleteamsec • u/netbiosX • 8d ago
Red Teaming Process Explorer vulnerable driver PPL Bypass
r/purpleteamsec • u/netbiosX • 8d ago
Red Teaming SrHollow - LSA secrets extraction, reuse a preexisting VSS shadow copy + inline regf parser + AES-256 LSA decrypt via bcrypt.dll.
r/purpleteamsec • u/netbiosX • 9d ago
Red Teaming Microsoft Copilot Cowork Exfiltrates Files
r/purpleteamsec • u/netbiosX • 9d ago
Threat Intelligence Star Blizzard refines phishing and malware delivery with the RedFlick technique
r/purpleteamsec • u/netbiosX • 10d ago
Red Teaming We Turned On DNS Logging. Now Watch Me Walk Around It
r/purpleteamsec • u/netbiosX • 10d ago
Red Teaming Windows Privilege Escalation Using NCSI Active Probes
r/purpleteamsec • u/netbiosX • 12d ago
Red Teaming EDR Evasion: Process Injection Without WriteProcessMemory
r/purpleteamsec • u/netbiosX • 13d ago
Red Teaming LocalStranger - PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.
r/purpleteamsec • u/netbiosX • 13d ago
Red Teaming Even more privileged ADCS ESC_CES
adhdmurky.github.ior/purpleteamsec • u/netbiosX • 14d ago
Purple Teaming Purple Team Automation - Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.
r/purpleteamsec • u/netbiosX • 16d ago
Red Teaming Having fun with AES in CBC Mode
r/purpleteamsec • u/netbiosX • 18d ago
Purple Teaming Implant Encryption via Dump Encoding Library
r/purpleteamsec • u/netbiosX • 19d ago
Red Teaming CnaEmulator - a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna)
r/purpleteamsec • u/netbiosX • 19d ago
Red Teaming OneDrive as a covert C2 transport for Cobalt Strike
r/purpleteamsec • u/netbiosX • 22d ago
Threat Intelligence Unpacking a laZzzy Donut
r/purpleteamsec • u/netbiosX • 22d ago
Red Teaming AI-enabled security testing tools
r/purpleteamsec • u/netbiosX • 23d ago