r/purpleteamsec 13h ago

Red Teaming CouchPotato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege. Service account || Admin -> NT system

Thumbnail
github.com
3 Upvotes

r/purpleteamsec 1d ago

Red Teaming Simulating legitimate Active Directory services on the network: the the case of GPO exploitation

Thumbnail
synacktiv.com
5 Upvotes

r/purpleteamsec 2d ago

Blue Teaming Detect DLL search order hijacking with a single field

Thumbnail
elastic.co
2 Upvotes

r/purpleteamsec 2d ago

Red Teaming Abusing Azure VMs - When Bitlocker Recovery Turns into an Attack Vector

Thumbnail
alteredsecurity.com
3 Upvotes

r/purpleteamsec 2d ago

Blue Teaming A scenario to evaluate your Agentic SOC

Thumbnail
unsecure.sh
2 Upvotes

r/purpleteamsec 3d ago

Threat Hunting Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database

Thumbnail
guidepointsecurity.com
1 Upvotes

r/purpleteamsec 4d ago

Red Teaming When it Snows it Pours - Anatomy of a ServiceNow Red Team

Thumbnail
mdsec.co.uk
5 Upvotes

r/purpleteamsec 5d ago

Red Teaming Stratum-c2: Cloud-native C2 framework using cloud storage as dead-drop communication channel

Thumbnail
github.com
2 Upvotes

r/purpleteamsec 7d ago

Blue Teaming I'm in your logs now: deceiving analysts and blinding EDRs

Thumbnail
falconforce.nl
9 Upvotes

r/purpleteamsec 6d ago

Red Teaming MassDriver - Proxying sensitive API calls from shellcode to artifact for CET-compatible clean call stacks.

Thumbnail
github.com
3 Upvotes

r/purpleteamsec 7d ago

Red Teaming RPC-Triage: statically map Windows RPC attack surface and rank the interfaces worth digging into

Thumbnail
github.com
3 Upvotes

Been working on Windows RPC/ALPC research and built this to make the first pass across a lot of PE files easier. It statically recovers RPC/MIDL/NDR internals, endpoints, security state and method-level input signals, then ranks interfaces using an AHP/Saaty-based model for reachability + surface. Each result has a scoring receipt so you can see why it ranked where it did, and questionable extraction gets flagged instead of silently trusted. No PDBs, no live endpoint mapper, no target execution.


r/purpleteamsec 8d ago

Threat Intelligence SLEEPWALKER: A Passive Backdoor With Its Own Command Language

Thumbnail r136a1.dev
3 Upvotes

r/purpleteamsec 8d ago

Threat Hunting Threat Hunting using Pair Probabilities

Thumbnail
medium.com
1 Upvotes

r/purpleteamsec 8d ago

Red Teaming CrystalPotato: Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run commands, reverse shells or add users

Thumbnail
github.com
2 Upvotes

r/purpleteamsec 8d ago

Purple Teaming Code Execution via Text Template Files | Playbook & Detection

Thumbnail
ipurple.team
2 Upvotes

r/purpleteamsec 9d ago

Blue Teaming Auditing Microsoft Defender and Intune Configuration Changes

Thumbnail
jeffreyappel.nl
7 Upvotes

r/purpleteamsec 9d ago

Red Teaming Mimic: Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic phishing simulations, easily injected via reverse proxy.

Thumbnail
github.com
9 Upvotes

r/purpleteamsec 10d ago

Red Teaming Collection of Beacon Object Files (BOFs)

Thumbnail
github.com
3 Upvotes

r/purpleteamsec 12d ago

Threat Intelligence BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Thumbnail
research.checkpoint.com
4 Upvotes

r/purpleteamsec 12d ago

Threat Intelligence SynkLoader: when you throw in everything but the kitchen sink

Thumbnail
expel.com
6 Upvotes

r/purpleteamsec 12d ago

Threat Intelligence Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025

Thumbnail
esentire.com
3 Upvotes

r/purpleteamsec 13d ago

Red Teaming A security-research Proof-of-Concept (POC) demonstrating hardware-breakpoint (CPU debug register) based function hooking as an alternative to traditional in-memory code patching.

Thumbnail
github.com
1 Upvotes

r/purpleteamsec 13d ago

Red Teaming BOFScale: A CDN-Fronted Tailnet from a BOF-PE

Thumbnail
netspi.com
2 Upvotes

r/purpleteamsec 15d ago

Red Teaming BusyWork: Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR

Thumbnail
github.com
6 Upvotes

r/purpleteamsec 14d ago

Red Teaming DutchOven - Application-scoped Windows network brownouts in native C and BOF form

Thumbnail
github.com
1 Upvotes