"emerald-template is a CMake-based project template designed for developing and debugging Reflective DLL Loaders using the Crystal Palace linker."
"This allows for source-code level debugging of your loader logic from Windows (and theoretically Linux) systems"
github.com/0xTriboulet/...
10.12.2025 12:12
π 5
π 1
π¬ 0
π 0
def con 34 and 35 save the date calendar image
Good News, Everyone! We have the official dates for #DEFCON34! And to make up for the delay, we also have the dates for #DEFCON35!
Please join us at the Las Vegas Convention Center August 6-9 in 2026 and August 5-8 in 2027.
Save the dates, friends. It'll be here before you know it.
#defcon
29.10.2025 18:49
π 36
π 17
π¬ 2
π 3
NTLM relay research is evolving!
Join Nick Powers & @tw1sm.bsky.social TOMORROW as they share new methods to enumerate EPA enforcement across MSSQL, HTTP, & moreβand intro RelayInformer, expanding attacker-perspective coverage for key protocols.
Grab your spot β ghst.ly/oct-web-bsky
29.10.2025 22:25
π 8
π 4
π¬ 0
π 0
And it's released! π
github.com/ofasgard/exe...
I've tested it with Rubeus and Seatbelt and a variety of different arguments, and it seems to be pretty stable as far as I can tell. If anyone uses this PICO and encounters bugs or instability, please let me know!
16.10.2025 16:13
π 5
π 3
π¬ 0
π 0
1 little known secret of help.exe
www.hexacorn.com/blog/2025/10...
19.10.2025 01:13
π 5
π 2
π¬ 0
π 0
Pop a vendor website, replace their /.well-known/security.txt with your own rogue contact info, and wait for the bugs to roll in.
20.10.2025 19:41
π 7
π 1
π¬ 0
π 0
Post-ex Weaponization: An Oral History
This is "Post-ex Weaponization: An Oral History" by AFF-WG on Vimeo, the home for high quality videos and the people who love them.
Why plant a Tradecraft Garden?
April 2025, I talked to my camera about how tradecraft may go the route we saw vuln research go years ago, red teaming's retreat to self-protective secrecy, and the opportunity I see for a public tradecraft ecosystem. This starts @ 1:16:00
vimeo.com/1074106659#t...
14.10.2025 16:57
π 10
π 5
π¬ 0
π 0
MacroPack v2.8.7 is out!
New GUI & updated EDR evasion! New features include Advanced LNK spoofing, expanded .NET obfuscation, and ML-evasion.
For authorized red-team use!
#RedTeam #offensivesecurity
14.10.2025 16:10
π 3
π 2
π¬ 0
π 0
Working on a fun Crystal Palace loader that hooks APIs and pushes them through a call stack spoofing PICO.
04.10.2025 19:59
π 8
π 2
π¬ 1
π 0
RunDll Exporters
www.hexacorn.com/blog/2025/09...
19.09.2025 23:14
π 8
π 2
π¬ 1
π 0
This report from @interseclab.bsky.social on how a Chinese company is exporting some of the capabilities of "The Great Wall of China" to other autocratic countries is INSANELY INTERESTING:
interseclab.org/wp-content/u...
*EVERY Page is worth reading*
Some interesting tidbits in the thread
14.09.2025 18:15
π 3
π 1
π¬ 1
π 0
DLL ForwardSideloading
www.hexacorn.com/blog/2025/08...
using forwarded DLL functions for sideloading purposes
19.08.2025 22:32
π 11
π 5
π¬ 1
π 0
DLL ForwardSideloading, Part 2
www.hexacorn.com/blog/2025/09...
03.09.2025 23:36
π 9
π 2
π¬ 1
π 0
Juicing ntds.dit Files to the Last Drop - SpecterOps
Discover the latest enhancements to the DSInternals PowerShell module, including the Golden dMSA Attack and support for LAPS, trust passwords, or BitLocker recovery keys.
The DSInternals PowerShell module just got an upgrade! π₯
Updates include:
β
Golden dMSA Attack
β
Full LAPS support
β
Trust password & BitLocker recovery key extraction
β
Read-only domain controller database compatibility
Read more from Michael Grafnetter: ghst.ly/412rZ7F
14.08.2025 17:21
π 5
π 4
π¬ 0
π 0
Certify 2.0 - SpecterOps
Certify 2.0 features a suite of new capabilities and usability enhancements. This blogpost introduces changes and features additions.
The AD CS security landscape keeps evolving, and so does our tooling. π οΈ
Valdemar CarΓΈe drops info on Certify 2.0, including a suite of new capabilities and refined usability improvements. ghst.ly/45IrBxI
11.08.2025 20:38
π 11
π 8
π¬ 0
π 0
08.08.2025 02:15
π 1
π 0
π¬ 0
π 0
BloodHound 8.0 is here.
A big leap forward in identity security prevention.
Now weβre able to model attack paths across the entire modern enterprise stack.
Our folks will be at #BlackHat next week to show off a few examples. Check it out:
29.07.2025 17:23
π 9
π 1
π¬ 0
π 0
Weβre trying something new.
www.preludesecurity.com/runtime-memo...
31.07.2025 10:59
π 4
π 1
π¬ 0
π 0
[BLOG]
Integrating Tradecraft Garden PIC loaders into Cobalt Strike
rastamouse.me/harvesting-t...
08.06.2025 01:43
π 9
π 5
π¬ 0
π 1
Voice clones are easy.
Be suspicious even if a call appears to be from someone you know.
Alsoβ¦Donβt set up voice authentication for banking.
30.05.2025 15:52
π 34
π 13
π¬ 0
π 0
Update on May 29 Outage
Read SentinelOne's update on the May 29, 2025 outage here.
SentinelOne experienced hours-long outages today.
"Customer endpoints are still protected at this time, but managed response services will not have visibility," per blog post.
"Our initial RCA suggests this is not a security incident."
www.sentinelone.com/blog/update-...
29.05.2025 18:49
π 3
π 1
π¬ 0
π 0