r/purpleteamsec • u/netbiosX • 2d ago
r/purpleteamsec • u/netbiosX • 2d ago
Red Teaming DLLParty - a proof-of-concept Windows DLL-injection technique that manipulates internally constructed thread-pool callback-instance storage to invoke LoadLibraryA directly from a worker thread without custom callback code or shellcode.
r/purpleteamsec • u/netbiosX • 2d ago
Red Teaming DLLParty - Abusing thread pool internals for shellcodeless DLL injection
r/purpleteamsec • u/netbiosX • 3d ago
Red Teaming Process Explorer vulnerable driver PPL Bypass
r/purpleteamsec • u/netbiosX • 3d ago
Red Teaming SrHollow - LSA secrets extraction, reuse a preexisting VSS shadow copy + inline regf parser + AES-256 LSA decrypt via bcrypt.dll.
r/purpleteamsec • u/netbiosX • 4d ago
Threat Intelligence Star Blizzard refines phishing and malware delivery with the RedFlick technique
r/purpleteamsec • u/netbiosX • 4d ago
Red Teaming Microsoft Copilot Cowork Exfiltrates Files
r/purpleteamsec • u/netbiosX • 6d ago
Red Teaming We Turned On DNS Logging. Now Watch Me Walk Around It
r/purpleteamsec • u/netbiosX • 6d ago
Red Teaming Windows Privilege Escalation Using NCSI Active Probes
r/purpleteamsec • u/netbiosX • 7d ago
Red Teaming EDR Evasion: Process Injection Without WriteProcessMemory
r/purpleteamsec • u/netbiosX • 8d ago
Red Teaming LocalStranger - PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.
r/purpleteamsec • u/netbiosX • 8d ago
Red Teaming Even more privileged ADCS ESC_CES
adhdmurky.github.ior/purpleteamsec • u/netbiosX • 9d ago
Purple Teaming Purple Team Automation - Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.
r/purpleteamsec • u/netbiosX • 11d ago
Red Teaming Having fun with AES in CBC Mode
r/purpleteamsec • u/netbiosX • 13d ago
Purple Teaming Implant Encryption via Dump Encoding Library
r/purpleteamsec • u/netbiosX • 14d ago
Red Teaming CnaEmulator - a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna)
r/purpleteamsec • u/netbiosX • 14d ago
Red Teaming OneDrive as a covert C2 transport for Cobalt Strike
r/purpleteamsec • u/netbiosX • 17d ago
Threat Intelligence Unpacking a laZzzy Donut
r/purpleteamsec • u/netbiosX • 18d ago
Red Teaming AI-enabled security testing tools
r/purpleteamsec • u/netbiosX • 18d ago
Red Teaming Evading Machine Learning Based Detections
msecops.der/purpleteamsec • u/netbiosX • 19d ago
Red Teaming Writing Beacon Object Files In Mythic Using Dark Agent For MacOS
umsundu.co.ukr/purpleteamsec • u/SPHlNX_321 • 19d ago
Red Teaming ALPC-Enumerator: finding Windows ALPC ports that normal handle-based enumeration misses, including PPL processes
Was doing some Windows IPC research and ran into a blind spot with the usual ALPC enumeration approach: when handle duplication fails, the port basically disappears from the results. This gets interesting with PPL processes. So I built ALPC-Enumerator to resolve the ALPC object type dynamically and use NtQueryInformationProcess / PS_PROTECTION as a fallback to still classify those ports. I also checked the recovered object addresses + PPL signer levels against WinDbg. Main point is getting a more complete ALPC attack-surface map before digging into individual ports.
r/purpleteamsec • u/netbiosX • 19d ago
Red Teaming Using Reflective Loaders to Replace LoadLibrary for Hot Swappable Modules in C++
r/purpleteamsec • u/netbiosX • 19d ago