Sign in

Armada

@armada-ops.com
8 followers 10 following 80 posts

Armada is the proactive services practice of @risk3sixty armada.risk3sixty.com

PostsRepliesMedia
Armada @armada-ops.com · 24/07/2026
Full technical report, including the detection signals that actually catch this class of tool: armada.risk3sixty.com/resources/de...
armada.risk3sixty.com
DestinyML Reverse Engineering Report - Armada Proactive Services, powered by risk3sixty
Armada researchers reverse engineered a commercial AI-powered game cheat to uncover how it avoids anti-cheat detection. Download the full technical report.
000
Armada @armada-ops.com · 24/07/2026
Full research on how it works: Part 1 - armada.risk3sixty.com/blog/reverse... Part2 - armada.risk3sixty.com/blog/what-ai...
armada.risk3sixty.com
Reverse Engineering Commercial Video Game AI Cheat
This post is part 1 of a 2-part series that provides extensive technical details on a commercial AI video game cheat.
100
Armada @armada-ops.com · 24/07/2026
Next Friday, 7/31, 1pm ET, our own Steve Guris (who did the RE work) goes deep with Nick Swink on The Operator View, LIVE. Bring your questions, we're answering them on air. www.youtube.com/watch?v=IkBo...
youtube.com
The Operator View July 2026 - Reverse Engineering Video Game Cheats w/ Steve Guris
YouTube video by Armada Advanced Security
100
Armada @armada-ops.com · 24/07/2026
An "AI aimbot" that never touches game memory. It just watches the screen, like you do, except it doesn't blink, and it's running a YOLOv5 model. We reverse engineered DestinyML, a commercial Destiny 2 cheat, and it's wilder than it sounds.
youtube.com
The Operator View July 2026 - Reverse Engineering Video Game Cheats w/ Steve Guris
YouTube video by Armada Advanced Security
100
Armada @armada-ops.com · 13/05/2026
Watch the full episode here: youtube.com/live/s4I14Xh... #CyberSecurity #RedSun #TheOperatorView #InfoSec #RedTeam #WindowsSecurity #ZeroDay #ArmadaOps #Microsoft #ResponsibleDisclosure
youtube.com
The Operator View Apr 2026 - Windows LPE 0-day Vulnerability
YouTube video by Armada Advanced Security
000
Armada @armada-ops.com · 13/05/2026
If your security model treats your AV as an untouchable "trusted" process, you are missing the battlefield. RedSun proves that the more power a security tool has, the more dangerous it is when the logic fails.
100
Armada @armada-ops.com · 13/05/2026
Since Defender operates with SYSTEM permissions, it can write to any driver or directory. The exploit uses this to copy itself to a privileged location and spawn the Tiering Engine Service as NT AUTHORITY\SYSTEM.
100
Armada @armada-ops.com · 13/05/2026
The exploit relies on a logical flaw during Defender's file rewrite process. By locking a flagged file and swapping it with a symlink before Defender completes its triage, an attacker hijacks the privileged write.
100
Armada @armada-ops.com · 13/05/2026
Windows Defender is the new vanguard for Local Privilege Escalation. Clip #1 from the latest 'The Operator View' breaks down the RedSun LPE and the TOCTOU race condition that turns MsMpEng.exe into a payload delivery system: youtube.com/shorts/pS5km...
youtube.com
YouTube
Share your videos with friends, family, and the world
100
Armada @armada-ops.com · 24/04/2026
#CyberSecurity #ZeroDay #LiveStream #InfoSec #ThreatIntel #TheOperatorView #Armada #RedSun #WindowsSecurity
000
Armada @armada-ops.com · 24/04/2026
Nick Swink will be performing a live code breakdown and exploit demo. If you are relying on a vendor's initial patch to secure your perimeter, you need to see this bypass in action. See you at 1:00 PM EST.
100
Armada @armada-ops.com · 24/04/2026
When MSRC dismissed the initial report, they created a massive operational blind spot. RedSun weaponizes a logic flaw in the kernel to achieve full SYSTEM-level access in milliseconds.
100
Armada @armada-ops.com · 24/04/2026
Vendor patches are assumptions. Exploitation is the ground truth. The Armada team is broadcasting The Operator View live today at 1:00 PM EST to dissect the RedSun Windows LPE 0-day by Nightmare-Eclipse. Join the live stream here: youtube.com/live/s4I14Xh...
youtube.com
The Operator View Apr 2026 - Windows LPE 0-day Vulnerability
YouTube video by Armada Advanced Security
100
Armada @armada-ops.com · 20/04/2026
By the time a ransom note is visible, the data is already gone. If your defense relies on stopping the encryption binary, you will lose. You must break the kill chain at the source by neutralizing infostealer credential theft and enforcing strict identity perimeters.
000
Armada @armada-ops.com · 20/04/2026
Once inside, the modern ransomware playbook is exfiltration-first. In the Change Healthcare incident, RansomHub operators spent nine days quietly exfiltrating 190 million records before deploying the ALPHV encryption payload.
100
Armada @armada-ops.com · 20/04/2026
Threat actors rarely burn 0-days for initial access anymore. They use compromised credentials harvested by infostealers. Infostealers are the vanguard. They feed the Initial Access Brokers, who supply the Ransomware-as-a-Service (RaaS) affiliates.
100
Armada @armada-ops.com · 20/04/2026
Ransomware is not the attack. It is the smoke grenade deployed after the attack is already over. To close our Infostealer series, the Armada team breaks down the operational reality of the Change Healthcare breach: youtube.com/shorts/9Sl0Q...
youtube.com
YouTube
Share your videos with friends, family, and the world
100
Armada @armada-ops.com · 17/04/2026
#ZeroDay #WindowsSecurity #RedTeam #ThreatIntel #LPE #0day #RedSun #Armada #ArmadaOps #Cybersecurity #InfoSec #Windows #Vulnerability
000
Armada @armada-ops.com · 17/04/2026
Because Defender runs at the highest level, the attacker immediately gains NT AUTHORITY\SYSTEM. Vendor arrogance is not a security control. Join the webcast to see the technical ground truth of the RedSun attack path and how to detect the behavioral artifacts.
100
Armada @armada-ops.com · 17/04/2026
By combining the Cloud Files API with opportunistic locks, an attacker can pause execution and swap directories. Defender is tricked into writing the attacker's payload directly into System32.
100
Armada @armada-ops.com · 17/04/2026
The researcher attempted coordinated disclosure. MSRC ignored it. In retaliation, the PoC was dropped publicly. RedSun weaponizes Microsoft Defender against itself. It is a logic flaw in the cloud file rollback mechanism, turning the AV into the exploitation vehicle.
100
Armada @armada-ops.com · 17/04/2026
1/4 When MSRC ignores a vulnerability report, the enterprise absorbs the blast radius. The RedSun 0-day is active in the wild because Microsoft dismissed the researcher. We are breaking down the exploit and the vendor failure live on Friday, April 24th over on Youtube: youtube.com/live/s4I14Xh...
youtube.com
The Operator View Apr 2026 - Windows LPE 0-day Vulnerability
YouTube video by Armada Advanced Security
100
Armada @armada-ops.com · 15/04/2026
A risk assessment built entirely on interviews is just a collection of assumptions. The Armada team breaks down why traditional assessments fail, and how a "technical overlay" exposes the ground truth: youtube.com/shorts/JKG4r...
youtube.com
YouTube
Share your videos with friends, family, and the world
000
Armada @armada-ops.com · 10/04/2026
Check out the full webcast over on Youtube: youtube.com/live/nlDT1Bb...
youtube.com
Malicious Browser Extensions - The Operator View (Ep. 3)
YouTube video by Armada Advanced Security
000
Armada @armada-ops.com · 10/04/2026
If your organization relies on SaaS, your users' browsers are the front lines of your identity perimeter. You cannot secure a modern network without locking down the extension ecosystem. #ZeroTrust #CyberSecurity #BrowserSecurity #InfoSec #RedTeam #Armada #Google #GoogleChrome
000
Armada @armada-ops.com · 10/04/2026
Attackers do not need to diversify their exploit toolsets. They can focus entirely on weaponizing Chrome extensions, knowing a single malicious payload can achieve stealth session hijacking at scale.
100
Armada @armada-ops.com · 10/04/2026
Google Chrome is no longer just a browser. With 3.4 billion users and 65% of the global market share, it is the world's largest enterprise attack surface. For threat actors, this dominance creates the ultimate target of opportunity.
100
Armada @armada-ops.com · 10/04/2026
If 65% of your targets wear the exact same armor, you only need to engineer one weapon to pierce it. The Armada team breaks down the operational risk of the Google Chrome monoculture: youtube.com/shorts/Yinx_...
youtube.com
The 3.4 Billion User Blind Spot: Defending Google Chrome
YouTube video by Armada Advanced Security
200
Armada @armada-ops.com · 09/04/2026
Check out the rest of our infostealer series and more over on Youtube: www.youtube.com/@armadaops
youtube.com
Armada Advanced Security
Armada is risk3sixty’s elite offensive security division, helping mid-market and enterprise organizations proactively identify, validate, and remediate real-world threats. With a strong focus on Atta...
000
Armada @armada-ops.com · 09/04/2026
This is the reality of operational security. You rarely eliminate the threat. But by raising the bar, Chrome forced a stealth adversary to make operational noise. Process injection triggers EDR. By hardening the perimeter, defenders forced the enemy into the light.
000
Armada @armada-ops.com · 09/04/2026
This defensive shift broke the infostealer ecosystem overnight. But threat actors adapted. To bypass the DPAPI validation, malware must now rely on highly overt techniques like Process Injection, injecting malicious code directly into the active Chrome process.
100
Armada @armada-ops.com · 09/04/2026
Historically, malware quietly scraped saved Chrome passwords and decrypted them offline. Google neutralized this by tying decryption to the Windows DPAPI and the user's NTLM identity, enforcing a strict check that the decrypting process is Chrome itself.
100
Armada @armada-ops.com · 09/04/2026
When you harden a target, the adversary does not retreat. They escalate. The Armada team breaks down how Google Chrome forced infostealers to fundamentally change their tactics overnight: youtube.com/shorts/_JArf...
youtube.com
How Google Chrome Forced Infostealers to Evolve Overnight
YouTube video by Armada Advanced Security
200
Armada @armada-ops.com · 09/04/2026
Agreed. Continuous testing, in our opinion, is the next step once you've achieved a certain outcome from repeated penetration tests.
100
Armada @armada-ops.com · 08/04/2026
Defending a modern enterprise requires continuous operational security. You have to identify exposures, test your resilience, and adapt 24/7. Continuous ASM is the required evolution for securing a shifting perimeter.
000
Armada @armada-ops.com · 08/04/2026
Your attack surface is not static. Engineers spin up new cloud infrastructure daily, M&A introduces unknown networks, and highly innovative threat actors constantly change their exploit paths. An annual penetration test is a static defense against a dynamic threat.
200
Armada @armada-ops.com · 08/04/2026
Physical base security requires 24/7 monitoring. You have to evaluate changes in the landscape and adapt to adversary tactics in real-time. Checking the fence line once a month guarantees a breach. Your digital perimeter operates under the exact same rules.
100
Armada @armada-ops.com · 08/04/2026
You would never secure a military base by checking the perimeter once a year. Why are you doing it to your corporate network? The Armada team breaks down the military case for continuous Attack Surface Management (ASM): youtube.com/shorts/Yinx_...
youtube.com
YouTube
Share your videos with friends, family, and the world
100
Armada @armada-ops.com · 07/04/2026
Don't forget to check us out over on Youtube: www.youtube.com/@armadaops #BlueHammer #ZeroDay #ThreatIntelligence #CyberSecurity #RedTeam #VulnerabilityManagement #InfoSec #MSRC #Armada
youtube.com
Armada Advanced Security
Armada is risk3sixty’s elite offensive security division, helping mid-market and enterprise organizations proactively identify, validate, and remediate real-world threats. With a strong focus on Atta...
000
Armada @armada-ops.com · 07/04/2026
Attackers are already recompiling the public C code to evade basic EDR signatures. Because BlueHammer weaponizes Windows Defender against itself, defenders must rely on strict behavioral anomaly hunting until Microsoft issues an emergency patch.
000
Armada @armada-ops.com · 07/04/2026
The community is blaming the researcher, but the actual vulnerability is vendor bureaucracy. Treating security researchers like unpaid QA leads directly to public 0-day drops. Full disclosure forces action.
100
Armada @armada-ops.com · 07/04/2026
The exploit targets a TOCTOU symlink race condition in Windows Defender's signature update mechanism. Because Defender runs with the highest privileges, the exploit reliably grants an attacker SYSTEM-level access from a standard user account.
100
Armada @armada-ops.com · 07/04/2026
The "BlueHammer" Windows zero-day just proved that "responsible disclosure" is failing. A frustrated researcher leaked the unpatched Local Privilege Escalation (LPE) exploit on GitHub after MSRC allegedly mishandled the bug report.
200
Armada @armada-ops.com · 06/04/2026
The technical guide covers the exact methodology for: • Converting file structures and targeted Makefiles. • Linking external Windows libraries (like wininet). • Porting MASM assembly to GAS. • Optimizing compiler flags for payload size and symbol stripping.
000
Armada @armada-ops.com · 06/04/2026
Booting up a Windows VM just to compile a Visual Studio payload disrupts your workflow. If you operate from Linux, you need to know how to cross-compile Windows PoCs directly from your host. Read the Armada team's guide to using MinGW-w64 here: risk3sixty.com/blog/transfe...
100
Armada @armada-ops.com · 03/04/2026
They also achieve total DOM takeover, manipulating the SaaS application in real-time. If your organization relies on a SaaS-first identity perimeter, a compromised browser extension completely neutralizes your Zero Trust controls. Watch the full video here: youtube.com/live/nlDT1Bb...
000
Armada @armada-ops.com · 03/04/2026
Because extensions operate natively at the browser level, they act as an authorized insider threat. They bypass these flags to silently scrape local storage and all cookies, resulting in a frictionless MFA bypass.
110
Armada @armada-ops.com · 03/04/2026
Security teams rely on HttpOnly attributes to protect session tokens from client-side JavaScript. This mitigates traditional XSS, but it provides zero defense against a weaponized extension operating inside your identity perimeter.
100
Armada @armada-ops.com · 03/04/2026
Your Zero Trust architecture has a fatal flaw: Weaponized browser extensions. XSS is limited by the HttpOnly flag. Silent browser compromise is not. The Armada team breaks down the ultimate vector for stealth session hijacking: youtube.com/shorts/drglc...
100
Armada @armada-ops.com · 02/04/2026
Because the user manually initiates the execution through the native Windows Run dialog, this tactic frequently bypasses standard EDR behavioral alerts. #InfoSec #CyberSecurity #RedTeam #Malware #Infostealer #Technology #Microsoft #ClickFix #Armada #ArmadaOps #Hacking #ThreatIntel
000