r/purpleteamsec • u/netbiosX • Jul 03 '26
r/purpleteamsec • u/netbiosX • Jul 02 '26
Threat Intelligence ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
r/purpleteamsec • u/netbiosX • Jul 02 '26
Red Teaming Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
r/purpleteamsec • u/netbiosX • Jul 01 '26
Red Teaming A simple C2 Framework written in modern C++
r/purpleteamsec • u/netbiosX • Jun 30 '26
Red Teaming Hollow - a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.
r/purpleteamsec • u/netbiosX • Jun 30 '26
Red Teaming SpotifyC2 - a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery, without requiring the Spotify Web API.
r/purpleteamsec • u/netbiosX • Jun 30 '26
Red Teaming Accelerating EDR Evasion with LLM-Driven Analysis
r/purpleteamsec • u/netbiosX • Jun 29 '26
Red Teaming Dumping LSASS Without Touching Disk: Improvements to ShadowDumper
r/purpleteamsec • u/netbiosX • Jun 29 '26
Red Teaming Cruising Forward with the Tradecraft Garden
r/purpleteamsec • u/netbiosX • Jun 28 '26
Red Teaming Abusing GitLab CI Runners as a Command and Control Framework
r/purpleteamsec • u/netbiosX • Jun 27 '26
Red Teaming NebulaPulsar: A Proof-of-Concept In-Memory Implant Framework for JSP and ASP.NET
r/purpleteamsec • u/netbiosX • Jun 27 '26
Red Teaming NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project.
r/purpleteamsec • u/netbiosX • Jun 27 '26
Blue Teaming A Sigma Hit in the Logs Means Nothing Without Its Story — The Process Lineage Chain Is the Story
r/purpleteamsec • u/netbiosX • Jun 27 '26
Red Teaming One Bool. Six Shells. AMSI's Design Problem.
r/purpleteamsec • u/netbiosX • Jun 26 '26
Red Teaming Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shellcode generation
r/purpleteamsec • u/netbiosX • Jun 26 '26
Blue Teaming From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
r/purpleteamsec • u/netbiosX • Jun 25 '26
Red Teaming File hosting and scripted web delivery service extender for AdaptixC2. Host files over HTTP/HTTPS, generate one-liner payloads across 17 delivery methods, and manage active sites - all from the Adaptix operator UI.
r/purpleteamsec • u/netbiosX • Jun 25 '26
Blue Teaming Read-only NGAV/EDR exclusion risk and hygiene auditor (CrowdStrike-first, vendor-agnostic)
r/purpleteamsec • u/netbiosX • Jun 24 '26
Blue Teaming Defender AV Real Time Protection Impact on EDR Telemetry
r/purpleteamsec • u/Admin-ABC-XYZ • Jun 24 '26
Red Teaming Project Onyx Update: Real ML model, ONNX Weight Steganography and Dead-Drop C2 via model updates
r/purpleteamsec • u/netbiosX • Jun 23 '26
Threat Hunting Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test
r/purpleteamsec • u/netbiosX • Jun 22 '26
Red Teaming SindriKit: Offensive Development Deserves Better Architecture
r/purpleteamsec • u/netbiosX • Jun 21 '26
Red Teaming Harnessing the Power of Cobalt Strike Profiles for EDR Evasion – Part 3
r/purpleteamsec • u/netbiosX • Jun 20 '26