XPN Infosec Blog
Experimenting with Jev for Offensive Security
Accelerating EDR Evasion with LLM-Driven Analysis
Disposable Tooling - Building LLM-Generated Mythic Agents from Prompt to Deployment
Prompt Engineering for Security Agents - A Measurable Approach with GEPA
Jailbreaking Local Models with JSON
Benchmarking Malicious Agents
Extracting creds with Foundation Model
The Accidental C2 - Exploring Dev Tunnels for Remote Access
An Evening with Claude (Code)
Administrator Protection Review
Tokenization Confusion
The SQL Server Crypto Detour
ADFS - Living in the Legacy of DRS
Identity Providers for RedTeamers
MacOS "DirtyNIB" Vulnerability
Okta for Red Teamers
LAPS 2.0 Internals
PNG Steganography from First Principles
Building a Custom Mach-O Memory Loader for macOS - Part 1
Restoring Dyld Memory Loading
WAM BAM - Recovering Web Tokens From Office
Exploring SCCM by Unobfuscating Network Access Accounts
g_CiOptions in a Virtualized World
NTLMquic
Object Overloading
Weird Ways to Run Unmanaged Code in .NET
Azure Application Proxy C2
Tailoring Cobalt Strike on Target
Bring Your Own VM - Mac Edition
The .NET Export Portal
We Need To Talk About MACL
MacOS Injection via Third Party Frameworks
Debugging into .NET
Hiding your .NET - COMPlus_ETWEnabled
Designing The Adversary Simulation Lab
Hiding your .NET - ETW
AWS Lambda Redirector
Testing your RedTeam Infrastructure
MacOS Filename Homoglyphs Revisited
Protecting Your Malware with blockdlls and ACG
Bypassing MacOS Privacy Controls
Inter-Realm Key Roasting (well... within the first 30 days)
Analysing RPC With Ghidra and Neo4j
Evading Sysmon DNS Monitoring
Exploring Mimikatz - Part 2 - SSP
Exploring Mimikatz - Part 1 - WDigest
Silencing Cylance: A Case Study in Modern EDRs
Building, Modifying, and Packing with Azure DevOps
Azure AD Connect for Red Teamers
How to Argue like Cobalt Strike
ActiveBreach, powered by Ethereum Blockchain
RunDLL32 your .NET (AKA DLL exports from .NET)
Cisco AMP - Bypassing Self-Protection
AppLocker CLM Bypass via COM
macOS Research Outtakes - File Extensions
Disabling MacOS SIP via a VirtualBox kext Vulnerability
Endpoint Security Self-Protection on MacOS
Escaping the Sandbox – Microsoft Office on MacOS
Exploring PowerShell AMSI and Logging Evasion
Exploiting CVE-2018-1038 - Total Meltdown
Understanding and Evading Get-InjectedThread
Exploring Cobalt Strike's ExternalC2 framework
Moving jobs and exploiting flash (CVE-2018-4878)
Universal XSS via Evernote WebClipper
Exploiting Windows 10 Kernel Drivers - NULL Pointer Dereference
Exploiting Windows 10 Kernel Drivers - Stack Overflow
Windows Anti-Debug techniques - OpenProcess filtering
Kernel Exploit Demo - Windows 10 privesc via WARBIRD
Alternative methods of becoming SYSTEM
Kerberos AD Attacks - More Roasting with AS-REP
Defcon 25 in Review
Setting Service Principal Names To Roast Accounts
Using machine account credentials during an engagement
Kerberos AD Attacks - Kerberoasting
ExplodingCan - A vulnerability review
Analysis of APT28 hospitality malware (Part 2)
Analysis of APT28 hospitality malware
How GitHub login detection banner works
Industroyer C2 Communication
Using Hopper scripting to analyse MacRansom
Reviewing the APT32 phishing malware
Exploiting with pwndbg - Solving PlaidCTF 2016 SmartStove
Revisiting PlaidCTF - bigpicture
PlaidCTF - no_mo_flo writeup
Linux ptrace introduction AKA injecting into sshd for fun
New Blog and the Technology that powers it
BSidesSF CTF - DNSCap Walkthrough
BSidesSF CTF - Steel Mountain: Sensors Walkthrough
BSidesSF CTF: b-64-b-tuff Walkthrough
ROP Primer - Walkthrough of Level 2
ROP Primer - Walkthrough of Level 1
ROP Primer - Walkthrough of Level 0
Radare2 - Using Emulation To Unpack Metasploit Encoders
Windows Server 2016 / Docker Privilege Escalation
Kentico CMS (< 9.0.42) SQLi
Offensive Forensics - Recovering Files
Github Desktop - DOM XSS
Extracting SQL Server Hashes From master.mdf
Linux USBIP overflow (CVE-2016-3955)
GitHub Desktop - RCE
Bettercap - Capturing NTLM Hashes
Xbox One Controller Hacking
SQL Server Authentication With Metasploit and MITM
Foomatic-RIP (CVE-2015-8560)
MS15-099 - Sharepoint XSS
From CSV to Meterpreter
About Me