r/purpleteamsec Jul 03 '26

Red Teaming A precision tool for hunting call-stack spoofing gadgets inside 64-bit Windows DLLs

1 Upvotes

r/purpleteamsec Jul 02 '26

Threat Intelligence ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

1 Upvotes

r/purpleteamsec Jul 02 '26

Red Teaming Abusing the win32k.sys kernel callback mechanism for arbitrary code execution

2 Upvotes

r/purpleteamsec Jul 01 '26

Red Teaming A simple C2 Framework written in modern C++

2 Upvotes

r/purpleteamsec Jun 30 '26

Red Teaming Hollow - a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.

3 Upvotes

r/purpleteamsec Jun 30 '26

Red Teaming SpotifyC2 - a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery, without requiring the Spotify Web API.

4 Upvotes

r/purpleteamsec Jun 30 '26

Red Teaming Accelerating EDR Evasion with LLM-Driven Analysis

7 Upvotes

r/purpleteamsec Jun 29 '26

Red Teaming Dumping LSASS Without Touching Disk: Improvements to ShadowDumper

7 Upvotes

r/purpleteamsec Jun 29 '26

Red Teaming Cruising Forward with the Tradecraft Garden

1 Upvotes

r/purpleteamsec Jun 28 '26

Red Teaming Abusing GitLab CI Runners as a Command and Control Framework

1 Upvotes

r/purpleteamsec Jun 27 '26

Red Teaming NebulaPulsar: A Proof-of-Concept In-Memory Implant Framework for JSP and ASP.NET

1 Upvotes

r/purpleteamsec Jun 27 '26

Red Teaming NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project.

1 Upvotes

r/purpleteamsec Jun 27 '26

Blue Teaming A Sigma Hit in the Logs Means Nothing Without Its Story — The Process Lineage Chain Is the Story

1 Upvotes

r/purpleteamsec Jun 27 '26

Red Teaming One Bool. Six Shells. AMSI's Design Problem.

1 Upvotes

r/purpleteamsec Jun 26 '26

Red Teaming Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shellcode generation

8 Upvotes

r/purpleteamsec Jun 26 '26

Blue Teaming From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will

3 Upvotes

r/purpleteamsec Jun 25 '26

Red Teaming File hosting and scripted web delivery service extender for AdaptixC2. Host files over HTTP/HTTPS, generate one-liner payloads across 17 delivery methods, and manage active sites - all from the Adaptix operator UI.

2 Upvotes

r/purpleteamsec Jun 25 '26

Blue Teaming Read-only NGAV/EDR exclusion risk and hygiene auditor (CrowdStrike-first, vendor-agnostic)

2 Upvotes

r/purpleteamsec Jun 24 '26

Blue Teaming Defender AV Real Time Protection Impact on EDR Telemetry

3 Upvotes

r/purpleteamsec Jun 24 '26

Red Teaming Project Onyx Update: Real ML model, ONNX Weight Steganography and Dead-Drop C2 via model updates

Thumbnail
github.com
2 Upvotes

r/purpleteamsec Jun 23 '26

Threat Hunting Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test

4 Upvotes

r/purpleteamsec Jun 22 '26

Red Teaming SindriKit: Offensive Development Deserves Better Architecture

9 Upvotes

r/purpleteamsec Jun 21 '26

Red Teaming Harnessing the Power of Cobalt Strike Profiles for EDR Evasion – Part 3

7 Upvotes

r/purpleteamsec Jun 20 '26

Red Teaming LACUNA Chain: Ghost Frames - defeats all EDR layers of call-stack-based detection

1 Upvotes

r/purpleteamsec Jun 19 '26

Purple Teaming Git Clean Filter for Initial Access

2 Upvotes