back to Red Team

All Red Team articles

Red Team → All Red Team articles

Red Team Premium
3 weeks ago

Persistence Techniques

Persistence turns a temporary foothold into a long-term presence. Registry run keys, scheduled tasks, Windows services, WMI event …

Red Team Premium
3 weeks ago

Custom Implant Development

Commercial C2 frameworks are well-signatured by EDR. Custom implants let red teams test defenses against tradecraft that isn't in …

Red Team Premium
3 weeks ago

AV/EDR Evasion

How EDR products hook user-mode APIs in ntdll.dll and collect telemetry through AMSI and ETW — and how security researchers unders…

Red Team Premium
3 weeks ago

Malware Development

PE format internals, position-independent shellcode, the VirtualAlloc/VirtualProtect loader pattern, payload encryption for static…

Red Team Premium
3 weeks ago

Sleep Obfuscation

C2 beacons spend most of their time sleeping. During sleep, the shellcode sits as a recognisable RX region in memory — trivially c…

Red Team Premium
3 weeks ago

Credential Dumping

One foothold, full domain: credential dumping extracts LSASS memory, SAM hashes, DPAPI blobs, and NTDS via DCSync — turning any ad…

Red Team Premium
3 weeks ago

Process Injection Techniques

How attackers hide malicious code inside trusted host processes — browser, svchost, explorer — so EDR sees legitimate process tele…

Red Team Premium
3 weeks ago

Lateral Movement

One foothold is a beachhead, not a win. Lateral movement is how a single compromised host becomes the whole domain: take credentia…

Red Team Premium
3 weeks ago

C2 Infrastructure Design

Picking a C2 framework is the easy part; the hard part is hosting it so it survives contact with defenders and can't be traced bac…

Red Team Premium
3 weeks ago

LOLBins & LOLBAS

Why drop malware when Windows ships the tools? Every working LOLBin category with real commands: certutil/bitsadmin/desktopimgdown…