2026-02-12

Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons github.com/EricEsquivel/Cobalt #redteam

2026-02-10

📢 New article about GAC Hijacking to perform Code Execution and Persistence
📖 1x Playbook - A structured breakdown of the full approach
💡 3x Detection Opportunities
🏹 2x Threat Hunting Queries - Defender & Splunk

ipurple.team/2026/02/10/gac-hi #purpleteam

2026-02-04

CustomDpapi: Calling the undocumented DPAPI RPC interface directly, no more calling public CryptUnprotectData! github.com/EvilBytecode/Custom #redteam

2026-02-03

An open-source port/reimplementation of the Cobalt Strike BOF Loader github.com/CodeXTF2/Cobaltstri #redteam

2026-01-14

Wait, Why is my WebClient Started?: SCCM Hierarchy Takeover via NTLM Relay to LDAP specterops.io/blog/2026/01/14/ #redteam

2026-01-12

📢 EDR Silencing
📖 1x Playbook - A structured breakdown of the full approach
💡 6x Procedures - Practical, reproducible techniques mapped to real-world operator workflows
🚨 1x Sigma Rule - To help defenders spot this activity
🎯 A compact, practical resource for detection engineers and purple team operators.
💭 Would love your thoughts.

ipurple.team/2026/01/12/edr-si

2026-01-04

DbgNexum - a Proof-of-Concept for injecting shellcode using the Windows Debugging API and Shared Memory (File Mapping) github.com/dis0rder0x00/DbgNex

2024-12-08

Invoke-Stealth - automate the obfuscation process of any script written in PowerShell with different techniques github.com/JoelGMSec/Invoke-St #redteam

2024-12-07

A situational awareness Python script to help you find where to put your beacons rwxstoned.github.io/2024-12-06 #redteam

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst