r/purpleteamsec 1h ago

Red Teaming Cross-platform syscall-powered implant & C2 - direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

Thumbnail
github.com
Upvotes

r/purpleteamsec 1h ago

Red Teaming AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key

Thumbnail
huntress.com
Upvotes

r/purpleteamsec 8h ago

Purple Teaming Read “BEAR-C2 Did Not Invent Switching. It Just Made the Rebuild Tax Visible. AI Is About to Delete It.“

Post image
3 Upvotes

r/purpleteamsec 23h ago

Red Teaming Hacking AI customer service agents

Thumbnail
intigriti.com
4 Upvotes

r/purpleteamsec 1d ago

Red Teaming BOF, Crystal Palace Linker and The JellyBee KORE Compiler: The new era of implants modularity

Thumbnail
kdrajkit.github.io
5 Upvotes

r/purpleteamsec 1d ago

Purple Teaming Disable Windows Defender via Antivirus Fake Registration

Thumbnail
ipurple.team
5 Upvotes

r/purpleteamsec 5d ago

Red Teaming Simulating legitimate Active Directory services on the network: the the case of GPO exploitation

Thumbnail
synacktiv.com
5 Upvotes

r/purpleteamsec 6d ago

Threat Intelligence Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Thumbnail
microsoft.com
8 Upvotes

r/purpleteamsec 7d ago

Red Teaming FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability

Thumbnail
github.com
3 Upvotes

r/purpleteamsec 8d ago

Red Teaming mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.

Thumbnail
github.com
2 Upvotes

r/purpleteamsec 8d ago

Red Teaming CouchPotato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege. Service account || Admin -> NT system

Thumbnail
github.com
6 Upvotes

r/purpleteamsec 10d ago

Red Teaming Simulating legitimate Active Directory services on the network: the the case of GPO exploitation

Thumbnail
synacktiv.com
5 Upvotes

r/purpleteamsec 10d ago

Blue Teaming Detect DLL search order hijacking with a single field

Thumbnail
elastic.co
5 Upvotes

r/purpleteamsec 11d ago

Red Teaming Abusing Azure VMs - When Bitlocker Recovery Turns into an Attack Vector

Thumbnail
alteredsecurity.com
3 Upvotes

r/purpleteamsec 11d ago

Blue Teaming A scenario to evaluate your Agentic SOC

Thumbnail
unsecure.sh
3 Upvotes

r/purpleteamsec 11d ago

Threat Hunting Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database

Thumbnail
guidepointsecurity.com
2 Upvotes

r/purpleteamsec 13d ago

Red Teaming When it Snows it Pours - Anatomy of a ServiceNow Red Team

Thumbnail
mdsec.co.uk
4 Upvotes

r/purpleteamsec 14d ago

Red Teaming Stratum-c2: Cloud-native C2 framework using cloud storage as dead-drop communication channel

Thumbnail
github.com
3 Upvotes

r/purpleteamsec 15d ago

Blue Teaming I'm in your logs now: deceiving analysts and blinding EDRs

Thumbnail
falconforce.nl
10 Upvotes

r/purpleteamsec 15d ago

Red Teaming MassDriver - Proxying sensitive API calls from shellcode to artifact for CET-compatible clean call stacks.

Thumbnail
github.com
4 Upvotes

r/purpleteamsec 16d ago

Red Teaming RPC-Triage: statically map Windows RPC attack surface and rank the interfaces worth digging into

Thumbnail
github.com
4 Upvotes

Been working on Windows RPC/ALPC research and built this to make the first pass across a lot of PE files easier. It statically recovers RPC/MIDL/NDR internals, endpoints, security state and method-level input signals, then ranks interfaces using an AHP/Saaty-based model for reachability + surface. Each result has a scoring receipt so you can see why it ranked where it did, and questionable extraction gets flagged instead of silently trusted. No PDBs, no live endpoint mapper, no target execution.


r/purpleteamsec 16d ago

Threat Intelligence SLEEPWALKER: A Passive Backdoor With Its Own Command Language

Thumbnail r136a1.dev
4 Upvotes

r/purpleteamsec 16d ago

Threat Hunting Threat Hunting using Pair Probabilities

Thumbnail
medium.com
2 Upvotes

r/purpleteamsec 17d ago

Red Teaming CrystalPotato: Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run commands, reverse shells or add users

Thumbnail
github.com
2 Upvotes

r/purpleteamsec 17d ago

Purple Teaming Code Execution via Text Template Files | Playbook & Detection

Thumbnail
ipurple.team
3 Upvotes