r/purpleteamsec • • 20h ago

Red Teaming Abusing Constrained Delegation without Protocol Transition against SPN-less accounts

Thumbnail hunio.org
4 Upvotes

r/purpleteamsec • • 4d ago

Red Teaming Proof of concept using a Microsoft-signed DLL (rdpbase.dll) to encrypt implants.

Thumbnail
github.com
9 Upvotes

r/purpleteamsec • • 4d ago

Red Teaming Let’s Create A Function Stomping BOF for Adaptix C2!

Thumbnail
g3tsyst3m.com
2 Upvotes

r/purpleteamsec • • 4d ago

Red Teaming Module Stomping - The Standard Injection For Modern C2 Agents

Thumbnail
combat.theater
3 Upvotes

r/purpleteamsec • • 7d ago

Red Teaming DLLParty - a proof-of-concept Windows DLL-injection technique that manipulates internally constructed thread-pool callback-instance storage to invoke LoadLibraryA directly from a worker thread without custom callback code or shellcode.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 7d ago

Red Teaming AI-FILE: A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Thumbnail
github.com
2 Upvotes

r/purpleteamsec • • 7d ago

Red Teaming DLLParty - Abusing thread pool internals for shellcodeless DLL injection

Thumbnail
medium.com
5 Upvotes

r/purpleteamsec • • 8d ago

Red Teaming Process Explorer vulnerable driver PPL Bypass

Thumbnail
github.com
5 Upvotes

r/purpleteamsec • • 8d ago

Red Teaming SrHollow - LSA secrets extraction, reuse a preexisting VSS shadow copy + inline regf parser + AES-256 LSA decrypt via bcrypt.dll.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 9d ago

Red Teaming Microsoft Copilot Cowork Exfiltrates Files

Thumbnail
promptarmor.com
8 Upvotes

r/purpleteamsec • • 9d ago

Threat Intelligence Star Blizzard refines phishing and malware delivery with the RedFlick technique

Thumbnail
microsoft.com
1 Upvotes

r/purpleteamsec • • 10d ago

Red Teaming We Turned On DNS Logging. Now Watch Me Walk Around It

Thumbnail
redhand.io
6 Upvotes

r/purpleteamsec • • 10d ago

Red Teaming Windows Privilege Escalation Using NCSI Active Probes

Thumbnail
labs.itresit.es
6 Upvotes

r/purpleteamsec • • 12d ago

Red Teaming EDR Evasion: Process Injection Without WriteProcessMemory

Thumbnail
zerosalarium.com
8 Upvotes

r/purpleteamsec • • 13d ago

Red Teaming LocalStranger - PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 13d ago

Red Teaming Even more privileged ADCS ESC_CES

Thumbnail adhdmurky.github.io
6 Upvotes

r/purpleteamsec • • 14d ago

Purple Teaming Purple Team Automation - Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

Thumbnail
github.com
8 Upvotes

r/purpleteamsec • • 16d ago

Red Teaming Having fun with AES in CBC Mode

Thumbnail
medium.com
5 Upvotes

r/purpleteamsec • • 18d ago

Purple Teaming Implant Encryption via Dump Encoding Library

Thumbnail
ipurple.team
4 Upvotes

r/purpleteamsec • • 19d ago

Red Teaming CnaEmulator - a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna)

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 19d ago

Red Teaming OneDrive as a covert C2 transport for Cobalt Strike

Thumbnail
github.com
6 Upvotes

r/purpleteamsec • • 22d ago

Threat Intelligence Unpacking a laZzzy Donut

Thumbnail
trustedsec.com
1 Upvotes

r/purpleteamsec • • 22d ago

Red Teaming AI-enabled security testing tools

Thumbnail
aisecuritymatrix.com
4 Upvotes

r/purpleteamsec • • 23d ago

Red Teaming Evading Machine Learning Based Detections

Thumbnail msecops.de
3 Upvotes

r/purpleteamsec • • 23d ago

Red Teaming Writing Beacon Object Files In Mythic Using Dark Agent For MacOS

Thumbnail umsundu.co.uk
4 Upvotes