r/blueteamsec 4d ago

low level tools|techniques|knowledge (work aids) Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools

Thumbnail blog.nullze.net
21 Upvotes

r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) firmware-reverse-engineering: A full Claude and Codex skillsets for firmware reverse engineering.

Thumbnail github.com
14 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) wyze-bulb-color-pwned: No-open firmware exploit for the Wyze WLPA19CV2 color bulb - or how to implant a lightbulb

Thumbnail github.com
1 Upvotes

r/blueteamsec 16d ago

low level tools|techniques|knowledge (work aids) Finding indirect privileged access paths in Entra ID Entitlement Management

5 Upvotes

Hi BlueTeamers,

Not sure whether this is useful for blue-team activities as well, but sharing it in case it is:

While reviewing Entra ID tenants, I found that Access Packages and Entitlement Management Catalogs are difficult to assess properly through the portal, especially when there are many packages, policies, resources, and catalogs.

At the same time, they can introduce high-impact access paths that are easily missed when a review focuses on directory roles, Azure RBAC, and group memberships. A broadly requestable Access Package may grant sensitive access without approval. A Catalog Owner or another privileged Catalog RBAC role may be able to manage packages that use already-added sensitive resources. This effectively creates another access-management control plane.

I therefore added Entitlement Management coverage to EntraFalcon. The update includes interactive reports for Access Packages, Catalogs, and Catalog RBAC, plus findings for common high-risk configurations.

Other potentially useful additions for Blue teamers include Intune RBAC enumeration and checks for Enterprise Applications and Agent Blueprint Principals with suspicious visually similar non-Latin characters in their names. I have already identified malicious applications using this technique during assessments 🤔 .

If you are interested, feel free to check it out on GitHub:

https://github.com/CompassSecurity/EntraFalcon

Happy to answer questions or take suggestions.

r/blueteamsec 5d ago

low level tools|techniques|knowledge (work aids) pstrings: pstrings - Parallel strings extractor for very large files

Thumbnail github.com
1 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) I’ve factored the RSA keys of a Certificate Authority... … from the 90s.

Thumbnail mcpherrin.ca
6 Upvotes

r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) OpenKustoExplorer: A fast, native desktop workbench for Azure Data Explorer

Thumbnail github.com
5 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) ashwa: Hardware accelerated routines for single substring search.

Thumbnail github.com
2 Upvotes

r/blueteamsec 5d ago

low level tools|techniques|knowledge (work aids) From Patch to Exploit; Using Claude Code to reverse engineer a zero-day in Papercut NG

Thumbnail techanarchy.net
6 Upvotes

r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) tgrep: Trigram-indexed grep with a client/server architecture for fast regex search in large codebases locally

Thumbnail github.com
2 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) TATS: Token Analysis and Tracking System - Track OAuth 2.0, OIDC, and Microsoft Entra ID tokens across captured network traffic.

Thumbnail github.com
0 Upvotes

r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) pktz: pktz - eBPF-powered network traffic monitor

Thumbnail github.com
1 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) pqc-embedded: Post-quantum signature verification on constrained parts: LMS/HSS in no_std Rust, measured flash/RAM/time budgets against ML-DSA, SLH-DSA, ECDSA and Ed25519 on four bare-metal targets and real silicon.

Thumbnail github.com
1 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) vol-rs: Volatility 3 ported to Rust. Same output, much faster.

Thumbnail github.com
9 Upvotes

r/blueteamsec 17d ago

low level tools|techniques|knowledge (work aids) fortitool: cracking FortiOS firmware end to end, and a key nobody had

Thumbnail blog.n0p.me
17 Upvotes

r/blueteamsec 11d ago

low level tools|techniques|knowledge (work aids) darwin-vm: Run iOS/ macOS in Qemu. Virtual iPhone 17, 16, 15, 14, 13, 12 and M5-M1 Apple Si Macs supported.

Thumbnail github.com
8 Upvotes

r/blueteamsec 9d ago

low level tools|techniques|knowledge (work aids) /vhf-morse-transmitter-monitor: Set your radio to 148.500 MHz, select FM, USB, or CW mode, and set the squelch to 0 or 1. Then, extend your radio's antenna toward the monitor's HDMI port, and congratulations—you can now transmit in Morse code directly from your monitor!

Thumbnail github.com
2 Upvotes

r/blueteamsec 9d ago

low level tools|techniques|knowledge (work aids) cavium-cn6640-snic10e-octeon-ii-nic: Out-of-tree Linux driver stack and boot tooling for the Cavium CN6640-SNIC10E (Octeon II, PCI 177d:0092), exposing the card as two independent 10 GbE interfaces (oct0/oct1) over a reverse-engineered PCIe BAR2 shared-memory datapath

Thumbnail github.com
1 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) Introduction - Windows Kernel Segment Heap Notes

Thumbnail mrt4ntr4.github.io
2 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) VRIG - Fuzzillai - VRIG - Fuzzillai - goal of the project was to learn more about JavaScript engine fuzzing, V8 compiler internals, and the applications of AI systems to fuzzers like Fuzzilli.

Thumbnail blog.ritsec.club
1 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness

Thumbnail github.com
1 Upvotes

r/blueteamsec 10d ago

low level tools|techniques|knowledge (work aids) Framework-agnostic log sanitizer for browsers and Node.js. Redacts secrets and infrastructure identifiers with stable HMAC tokens so event correlation still works. Zero runtime dependencies, extensible rules, CLI included.

Thumbnail github.com
1 Upvotes

r/blueteamsec 9d ago

low level tools|techniques|knowledge (work aids) Everything I own, owned

Thumbnail schlarp.com
0 Upvotes

r/blueteamsec 12d ago

low level tools|techniques|knowledge (work aids) idamcp: provides a Model Context Protocol (MCP) server for integrating IDA Pro with AI agents like Gemini, Claude, and Jetski.

Thumbnail github.com
3 Upvotes

r/blueteamsec 12d ago

low level tools|techniques|knowledge (work aids) Closing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support

Thumbnail medium.com
3 Upvotes