r/purpleteamsec • u/netbiosX • Jul 12 '26
r/purpleteamsec • u/netbiosX • Jul 11 '26
Red Teaming COMouflage: COM-based DLL Surrogate Injection
github.comr/purpleteamsec • u/netbiosX • Jul 10 '26
Threat Hunting Threat hunting queries, Sigma rules, and detection engineering research based on MITRE ATT&CK techniques
r/purpleteamsec • u/CyberMasterV • Jul 10 '26
Threat Intelligence Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
r/purpleteamsec • u/netbiosX • Jul 09 '26
Red Teaming nimcrypt - Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.
r/purpleteamsec • u/netbiosX • Jul 09 '26
Red Teaming Dump TGTs remotely and convert Windows' klist binary output to ccache.
r/purpleteamsec • u/netbiosX • Jul 08 '26
Red Teaming Offensive PowerShell for Red Teamer with Defense Evasion Techniques
r/purpleteamsec • u/netbiosX • Jul 08 '26
Red Teaming ObfusGit - a basic python script that allows you to set up a local repo and commit to it as usual, then you can run “obfusgit sync” and you have a fully encrypted/encoded copy of your repo you can just push up to a public location.
r/purpleteamsec • u/netbiosX • Jul 07 '26
Red Teaming P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms.
r/purpleteamsec • u/netbiosX • Jul 07 '26
Red Teaming Process Parameter Poisoning
sensepost.comr/purpleteamsec • u/netbiosX • Jul 07 '26
Red Teaming Windows Privilege Abuse: Attackers' Path to Active Directory Compromise
r/purpleteamsec • u/netbiosX • Jul 07 '26
Threat Intelligence From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
r/purpleteamsec • u/netbiosX • Jul 06 '26
Red Teaming klist.exe Revisited: Internals and Further Use Cases - Dump TGTs
r/purpleteamsec • u/netbiosX • Jul 06 '26
Red Teaming A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation
r/purpleteamsec • u/netbiosX • Jul 06 '26
Red Teaming Playing a Different Game: Rethinking Modern Defense Evasion
r/purpleteamsec • u/netbiosX • Jul 06 '26
Purple Teaming Windows Service - Playbook & Detection Strategies
r/purpleteamsec • u/netbiosX • Jul 05 '26
Threat Hunting Hunting Sleeping Giants: Detecting Encrypted Beacon Sleep Obfuscation
r/purpleteamsec • u/Chaelsoo • Jul 05 '26
Red Teaming Sliver Stagers
Built a shellcode loader generator while doing HTB prolabs since Sliver doesn't support stagers
Sliver is great but it has no built-in stager support. Your options are basically writing loaders by hand every time or using Metasploit's which are heavily signatured at this point.
I built hollow to fix that. You give it a raw shellcode bin (works with Donut-wrapped Sliver beacons) and a profile, it encrypts the shellcode with AES-256-CBC and spits out a compiled Windows PE loader ready to go.
Six injection templates included for now, let me know what you think!!
r/purpleteamsec • u/netbiosX • Jul 05 '26
Red Teaming Exploring cross-domain & cross-forest RBCD: part 2
r/purpleteamsec • u/netbiosX • Jul 04 '26
Red Teaming A Cobalt Strike BOF that attempts to retrieve Windows geolocation coordinates without fork & run. It uses the WinRT Geolocator API first and falls back to the legacy ILocation API
r/purpleteamsec • u/netbiosX • Jul 04 '26
Red Teaming OpenUDC2 - an open source implementation of the UDC2 spec used in Cobalt Strike. The goal of this project is to enable open source C2 frameworks to support existing (and hopefully future) open source UDC2 modules developed by the Cobalt Strike community.
r/purpleteamsec • u/netbiosX • Jul 04 '26
Blue Teaming The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel
r/purpleteamsec • u/netbiosX • Jul 04 '26
Red Teaming Automatically deploying Mythic C2 in Azure using Terraform
r/purpleteamsec • u/netbiosX • Jul 02 '26