RSS.Social

XPN Infosec Blog

follow: @[email protected]

Posts

Experimenting with Jev for Offensive Security

Accelerating EDR Evasion with LLM-Driven Analysis

Disposable Tooling - Building LLM-Generated Mythic Agents from Prompt to Deployment

Prompt Engineering for Security Agents - A Measurable Approach with GEPA

Jailbreaking Local Models with JSON

Benchmarking Malicious Agents

Extracting creds with Foundation Model

The Accidental C2 - Exploring Dev Tunnels for Remote Access

An Evening with Claude (Code)

Administrator Protection Review

Tokenization Confusion

The SQL Server Crypto Detour

ADFS - Living in the Legacy of DRS

Identity Providers for RedTeamers

MacOS "DirtyNIB" Vulnerability

Okta for Red Teamers

LAPS 2.0 Internals

PNG Steganography from First Principles

Building a Custom Mach-O Memory Loader for macOS - Part 1

Restoring Dyld Memory Loading

WAM BAM - Recovering Web Tokens From Office

Exploring SCCM by Unobfuscating Network Access Accounts

g_CiOptions in a Virtualized World

NTLMquic

Object Overloading

Weird Ways to Run Unmanaged Code in .NET

Azure Application Proxy C2

Tailoring Cobalt Strike on Target

Bring Your Own VM - Mac Edition

The .NET Export Portal

We Need To Talk About MACL

MacOS Injection via Third Party Frameworks

Debugging into .NET

Hiding your .NET - COMPlus_ETWEnabled

Designing The Adversary Simulation Lab

Hiding your .NET - ETW

AWS Lambda Redirector

Testing your RedTeam Infrastructure

MacOS Filename Homoglyphs Revisited

Protecting Your Malware with blockdlls and ACG

Bypassing MacOS Privacy Controls

Inter-Realm Key Roasting (well... within the first 30 days)

Analysing RPC With Ghidra and Neo4j

Evading Sysmon DNS Monitoring

Exploring Mimikatz - Part 2 - SSP

Exploring Mimikatz - Part 1 - WDigest

Silencing Cylance: A Case Study in Modern EDRs

Building, Modifying, and Packing with Azure DevOps

Azure AD Connect for Red Teamers

How to Argue like Cobalt Strike

ActiveBreach, powered by Ethereum Blockchain

RunDLL32 your .NET (AKA DLL exports from .NET)

Cisco AMP - Bypassing Self-Protection

AppLocker CLM Bypass via COM

macOS Research Outtakes - File Extensions

Disabling MacOS SIP via a VirtualBox kext Vulnerability

Endpoint Security Self-Protection on MacOS

Escaping the Sandbox – Microsoft Office on MacOS

Exploring PowerShell AMSI and Logging Evasion

Exploiting CVE-2018-1038 - Total Meltdown

Understanding and Evading Get-InjectedThread

Exploring Cobalt Strike's ExternalC2 framework

Moving jobs and exploiting flash (CVE-2018-4878)

Universal XSS via Evernote WebClipper

Exploiting Windows 10 Kernel Drivers - NULL Pointer Dereference

Exploiting Windows 10 Kernel Drivers - Stack Overflow

Windows Anti-Debug techniques - OpenProcess filtering

Kernel Exploit Demo - Windows 10 privesc via WARBIRD

Alternative methods of becoming SYSTEM

Kerberos AD Attacks - More Roasting with AS-REP

Defcon 25 in Review

Setting Service Principal Names To Roast Accounts

Using machine account credentials during an engagement

Kerberos AD Attacks - Kerberoasting

ExplodingCan - A vulnerability review

Analysis of APT28 hospitality malware (Part 2)

Analysis of APT28 hospitality malware

How GitHub login detection banner works

Industroyer C2 Communication

Using Hopper scripting to analyse MacRansom

Reviewing the APT32 phishing malware

Exploiting with pwndbg - Solving PlaidCTF 2016 SmartStove

Revisiting PlaidCTF - bigpicture

PlaidCTF - no_mo_flo writeup

Linux ptrace introduction AKA injecting into sshd for fun

New Blog and the Technology that powers it

BSidesSF CTF - DNSCap Walkthrough

BSidesSF CTF - Steel Mountain: Sensors Walkthrough

BSidesSF CTF: b-64-b-tuff Walkthrough

ROP Primer - Walkthrough of Level 2

ROP Primer - Walkthrough of Level 1

ROP Primer - Walkthrough of Level 0

Radare2 - Using Emulation To Unpack Metasploit Encoders

Windows Server 2016 / Docker Privilege Escalation

Kentico CMS (< 9.0.42) SQLi

Offensive Forensics - Recovering Files

Github Desktop - DOM XSS

Extracting SQL Server Hashes From master.mdf

Linux USBIP overflow (CVE-2016-3955)

GitHub Desktop - RCE

Bettercap - Capturing NTLM Hashes

Xbox One Controller Hacking

SQL Server Authentication With Metasploit and MITM

Foomatic-RIP (CVE-2015-8560)

MS15-099 - Sharepoint XSS

From CSV to Meterpreter

About Me