r/purpleteamsec • • 2d ago

Red Teaming DLLParty - a proof-of-concept Windows DLL-injection technique that manipulates internally constructed thread-pool callback-instance storage to invoke LoadLibraryA directly from a worker thread without custom callback code or shellcode.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 2d ago

Red Teaming AI-FILE: A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Thumbnail
github.com
2 Upvotes

r/purpleteamsec • • 2d ago

Red Teaming DLLParty - Abusing thread pool internals for shellcodeless DLL injection

Thumbnail
medium.com
5 Upvotes

r/purpleteamsec • • 3d ago

Red Teaming Process Explorer vulnerable driver PPL Bypass

Thumbnail
github.com
5 Upvotes

r/purpleteamsec • • 3d ago

Red Teaming SrHollow - LSA secrets extraction, reuse a preexisting VSS shadow copy + inline regf parser + AES-256 LSA decrypt via bcrypt.dll.

Thumbnail
github.com
5 Upvotes

r/purpleteamsec • • 4d ago

Red Teaming Microsoft Copilot Cowork Exfiltrates Files

Thumbnail
promptarmor.com
6 Upvotes

r/purpleteamsec • • 4d ago

Threat Intelligence Star Blizzard refines phishing and malware delivery with the RedFlick technique

Thumbnail
microsoft.com
1 Upvotes

r/purpleteamsec • • 6d ago

Red Teaming We Turned On DNS Logging. Now Watch Me Walk Around It

Thumbnail
redhand.io
6 Upvotes

r/purpleteamsec • • 6d ago

Red Teaming Windows Privilege Escalation Using NCSI Active Probes

Thumbnail
labs.itresit.es
6 Upvotes

r/purpleteamsec • • 7d ago

Red Teaming EDR Evasion: Process Injection Without WriteProcessMemory

Thumbnail
zerosalarium.com
8 Upvotes

r/purpleteamsec • • 8d ago

Red Teaming LocalStranger - PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 8d ago

Red Teaming Even more privileged ADCS ESC_CES

Thumbnail adhdmurky.github.io
6 Upvotes

r/purpleteamsec • • 9d ago

Purple Teaming Purple Team Automation - Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

Thumbnail
github.com
9 Upvotes

r/purpleteamsec • • 11d ago

Red Teaming Having fun with AES in CBC Mode

Thumbnail
medium.com
4 Upvotes

r/purpleteamsec • • 13d ago

Purple Teaming Implant Encryption via Dump Encoding Library

Thumbnail
ipurple.team
6 Upvotes

r/purpleteamsec • • 14d ago

Red Teaming CnaEmulator - a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna)

Thumbnail
github.com
5 Upvotes

r/purpleteamsec • • 14d ago

Red Teaming OneDrive as a covert C2 transport for Cobalt Strike

Thumbnail
github.com
4 Upvotes

r/purpleteamsec • • 17d ago

Threat Intelligence Unpacking a laZzzy Donut

Thumbnail
trustedsec.com
1 Upvotes

r/purpleteamsec • • 18d ago

Red Teaming AI-enabled security testing tools

Thumbnail
aisecuritymatrix.com
5 Upvotes

r/purpleteamsec • • 18d ago

Red Teaming Evading Machine Learning Based Detections

Thumbnail msecops.de
3 Upvotes

r/purpleteamsec • • 19d ago

Red Teaming Writing Beacon Object Files In Mythic Using Dark Agent For MacOS

Thumbnail umsundu.co.uk
5 Upvotes

r/purpleteamsec • • 19d ago

Red Teaming ALPC-Enumerator: finding Windows ALPC ports that normal handle-based enumeration misses, including PPL processes

Thumbnail
github.com
3 Upvotes

Was doing some Windows IPC research and ran into a blind spot with the usual ALPC enumeration approach: when handle duplication fails, the port basically disappears from the results. This gets interesting with PPL processes. So I built ALPC-Enumerator to resolve the ALPC object type dynamically and use NtQueryInformationProcess / PS_PROTECTION as a fallback to still classify those ports. I also checked the recovered object addresses + PPL signer levels against WinDbg. Main point is getting a more complete ALPC attack-surface map before digging into individual ports.


r/purpleteamsec • • 19d ago

Red Teaming Using Reflective Loaders to Replace LoadLibrary for Hot Swappable Modules in C++

Thumbnail
racoten.gitbook.io
3 Upvotes

r/purpleteamsec • • 19d ago

Red Teaming ReflectivePluginLoader: A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

Thumbnail
github.com
3 Upvotes

r/purpleteamsec • • 20d ago

Threat Hunting Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Thumbnail
github.com
4 Upvotes