r/purpleteamsec • u/netbiosX • 13h ago
r/purpleteamsec • u/netbiosX • 1d ago
Red Teaming Simulating legitimate Active Directory services on the network: the the case of GPO exploitation
r/purpleteamsec • u/netbiosX • 2d ago
Blue Teaming Detect DLL search order hijacking with a single field
r/purpleteamsec • u/netbiosX • 2d ago
Red Teaming Abusing Azure VMs - When Bitlocker Recovery Turns into an Attack Vector
r/purpleteamsec • u/netbiosX • 2d ago
Blue Teaming A scenario to evaluate your Agentic SOC
r/purpleteamsec • u/netbiosX • 3d ago
Threat Hunting Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database
r/purpleteamsec • u/netbiosX • 4d ago
Red Teaming When it Snows it Pours - Anatomy of a ServiceNow Red Team
r/purpleteamsec • u/netbiosX • 5d ago
Red Teaming Stratum-c2: Cloud-native C2 framework using cloud storage as dead-drop communication channel
r/purpleteamsec • u/netbiosX • 7d ago
Blue Teaming I'm in your logs now: deceiving analysts and blinding EDRs
r/purpleteamsec • u/netbiosX • 6d ago
Red Teaming MassDriver - Proxying sensitive API calls from shellcode to artifact for CET-compatible clean call stacks.
r/purpleteamsec • u/SPHlNX_321 • 7d ago
Red Teaming RPC-Triage: statically map Windows RPC attack surface and rank the interfaces worth digging into
Been working on Windows RPC/ALPC research and built this to make the first pass across a lot of PE files easier. It statically recovers RPC/MIDL/NDR internals, endpoints, security state and method-level input signals, then ranks interfaces using an AHP/Saaty-based model for reachability + surface. Each result has a scoring receipt so you can see why it ranked where it did, and questionable extraction gets flagged instead of silently trusted. No PDBs, no live endpoint mapper, no target execution.
r/purpleteamsec • u/netbiosX • 8d ago
Threat Intelligence SLEEPWALKER: A Passive Backdoor With Its Own Command Language
r136a1.devr/purpleteamsec • u/netbiosX • 8d ago
Threat Hunting Threat Hunting using Pair Probabilities
r/purpleteamsec • u/netbiosX • 8d ago
Red Teaming CrystalPotato: Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run commands, reverse shells or add users
r/purpleteamsec • u/netbiosX • 8d ago
Purple Teaming Code Execution via Text Template Files | Playbook & Detection
r/purpleteamsec • u/netbiosX • 9d ago
Blue Teaming Auditing Microsoft Defender and Intune Configuration Changes
r/purpleteamsec • u/netbiosX • 9d ago
Red Teaming Mimic: Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic phishing simulations, easily injected via reverse proxy.
r/purpleteamsec • u/netbiosX • 10d ago
Red Teaming Collection of Beacon Object Files (BOFs)
r/purpleteamsec • u/netbiosX • 12d ago
Threat Intelligence BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
r/purpleteamsec • u/netbiosX • 12d ago
Threat Intelligence SynkLoader: when you throw in everything but the kitchen sink
r/purpleteamsec • u/netbiosX • 12d ago
Threat Intelligence Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025
r/purpleteamsec • u/netbiosX • 13d ago
Red Teaming A security-research Proof-of-Concept (POC) demonstrating hardware-breakpoint (CPU debug register) based function hooking as an alternative to traditional in-memory code patching.
r/purpleteamsec • u/netbiosX • 13d ago
Red Teaming BOFScale: A CDN-Fronted Tailnet from a BOF-PE
r/purpleteamsec • u/netbiosX • 15d ago