Sign in

BallisKit

@balliskit.bsky.social
114 followers 10 following 31 posts

BallisKit provides tooling and services to professional Pentesters & Red Teams. We develop MacroPack Pro and ShellcodePack. www.balliskit.com

PostsRepliesMedia
BallisKit @balliskit.bsky.social · 29/09/2026
Need to pivot through a macOS target during a Red Team operation? 🍎 Mirage C2 includes built-in SOCKS proxying, letting operators route traffic through a compromised Mac and reach resources beyond the initial foothold. Start it. Pivot. Keep moving. Part of DarwinOps by BallisKit. #RedTeam #macOS
011
BallisKit @balliskit.bsky.social · 18/09/2026
Introducing Mirage C2 🥷 — our new modular, in-memory macOS implant for DarwinOps. Shell, SOCKS proxy, secret extraction + private techniques for process injection, privilege escalation, TCC bypass & persistence. The full macOS attack chain, from initial access to post-exploitation. #redteam
012
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 08/09/2026
Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion, private .NET obfuscator and initial access ! We also started to integrate exploits for vulnerabilities abused in the wild! #redteam
021
BallisKit @balliskit.bsky.social · 18/08/2026
The new BallisKit tool soon to be released, an advanced macOS Mythic implant! All modular, in memory execution, includes private methods for process injection, TCC bypass, secret grabbing, persistance, malware behavior emulation, EDR Evasion, socks proxy, and more! #redteam #mirage
031
BallisKit @balliskit.bsky.social · 23/07/2026
Learn how to Weaponize Adaptix C2 with MacroPack and ShellcodePack! -> EXE and DLL Sideloading examples -> LNK spoofing PDF, HTA, Clickonce, etc. -> EDR Evasion options #redteam blog.balliskit.com/tutorial-ada...
blog.balliskit.com
Tutorial: Adaptix C2 with ShellcodePack and MacroPack
Adaptix C2 is a powerful and popular open source C2 framework. Adaptix gitbook can be found here. Sources are available on Adaptix C2…
111
BallisKit @balliskit.bsky.social · 20/05/2026
We updated our Sliver C2 + BallisKit tutorial to adapt to the latest Sliver version. Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads! More C2 tutorials available on the blog (Adaptix, Mythic) blog.balliskit.com/tutorial-sli...
blog.balliskit.com
Tutorial: Sliver C2 with BallisKit MacroPack and ShellcodePack
In this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam.
033
BallisKit @balliskit.bsky.social · 15/04/2026
New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events! #redteam
011
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 07/04/2026
I just wrote a tutorial explaining how to combine Adaptix C2 with MacroPack and ShellcodePack! This provides multiple initial access and EDR evasion options to Adaptix C2 users. Tutorial includes: LNK, CLickOnce, DLL Sideloading, Exe, HTA, etc! #redteam blog.balliskit.com/tutorial-ada...
blog.balliskit.com
Tutorial: Adaptix C2 with ShellcodePack and MacroPack
Adaptix C2 is a powerful and popular open source C2 framework. Adaptix gitbook can be found here. Sources are available on Adaptix C2…
011
BallisKit @balliskit.bsky.social · 18/03/2026
BallisKit ShellcodePack 2.8.1 is out! Focus: AppDomain injection & DLL sideloading, plus updated EDR evasion profiles. Learn how to backdoor .NET apps with our tutorial: blog.balliskit.com/appdomain-in... #redteam
blog.balliskit.com
AppDomain Injection -Backdooring .NET Framework Applications
AppDomain Injection is a technique that allows you to execute arbitrary code within .NET Framework applications by hijacking the AppDomain…
021
BallisKit @balliskit.bsky.social · 03/02/2026
MacroPack new version is out! 🥳 With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario! Also now everything can be leveraged with the new BallisKit GUI! 😎 #redteam
011
BallisKit @balliskit.bsky.social · 22/01/2026
DarwinOps just leveled up 🚀 Now supports AppleScript (SCPT), a format actively abused for macOS phishing. Plus new Ruby, VSCode , NPM & Homebrew payloads. A true macOS red team Swiss Army knife. AppleScript initial access guide 👇 blog.balliskit.com/macos-redtea...
blog.balliskit.com
MacOS Redteam 4: Initial Access with AppleScript
MacOS is often considered well protected, largely due to Gatekeeper. However, some execution vectors still operate under a different trust…
011
BallisKit @balliskit.bsky.social · 07/01/2026
Tutorial: DLL Sideloading and function proxying with ShellcodePack BallisKit ShellcodePack version 2.8.0 is available! This version comes with a new GUI, EDR evasion methods as well as enhanced DLL sideloading/hijacking. You can find the tutorial here: blog.balliskit.com/tutorial-dll...
blog.balliskit.com
Tutorial: DLL Sideloading and function proxying with ShellcodePack
DLL sideloading is a technique that allows an attacker to have a legitimate signed application run some malicious code on Windows. It work…
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 20/11/2025
PKG is a kind of MacOS MSI equivalent. It's also used as an initial access payload! Read how DarwinOps can be used to generate PKG for redteams. We also included a method to run the PKG without admin privileges -> Reduced number of clicks! #redteam blog.balliskit.com/macos-redtea...
blog.balliskit.com
MacOS Redteam 3: Initial Access with DarwinOps PKG
State of the art:
021
BallisKit @balliskit.bsky.social · 19/11/2025
We are preparing a new version of ShellcodePack! -> Automated and improved DLL sideloading/proxying capacity -> AppDomain injection -> New Responsive GUI! -> Many more new features And of course up to date EDR evasion :) #shellcodepack
021
BallisKit @balliskit.bsky.social · 14/10/2025
MacroPack v2.8.7 is out! New GUI & updated EDR evasion! New features include Advanced LNK spoofing, expanded .NET obfuscation, and ML-evasion. For authorized red-team use! #RedTeam #offensivesecurity
032
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 02/10/2025
MacOS red-team made practical — Objective-C implant for DarwinOps! Private Mythic C2 implant: lightweight (in-memory shellcode), post-exploitation, EDR & MDM evasion, integrates with DarwinOps + GateKeeper bypass. Contact us for more details! #RedTeam #macOS
022
BallisKit @balliskit.bsky.social · 24/09/2025
The next version of MacroPack is going to be huge! A new GUI, updated EDR bypass profiles, new evasion options, and many other things :) #redteam
011
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 17/09/2025
Binary injection vulnerabilities can be found in many MacOS apps. Those may be abused to bypass EDR, hide backdoor, access memory, or bypass TCC! DarwinOps provides - An advanced injection vulnerability scanner - A redteam scenario to exploit them #redteam blog.balliskit.com/macos-dylib-...
blog.balliskit.com
macOS DYLIB Injection at Scale: Designing a Self-Sufficient Loader
Let’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection)
042
BallisKit @balliskit.bsky.social · 08/09/2025
ShellcodePack 2.7.5 is now available! It includes updated bypass profiles for major EDRs We also improved: - ML detection evasion - ETW Patch - CallStack Spoofing ShellcodePack can be used to weaponize any raw shellcode or PE including DotNET, Go, and Rust :) #redteam
031
BallisKit @balliskit.bsky.social · 14/08/2025
Initial Access on MacOS made easy ! DarwinOps now supports DMG phishing profiles! Those are on shelf realistic templates with Gatekeeper bypass techniques :) This version also introduce a binary injection vulnerability scanner for MacOS! #redteam
021
BallisKit @balliskit.bsky.social · 01/08/2025
MacOS DMG phishing templates are coming in the next DarwinOps release! Ready to use, configurable, and with new GateKeeper bypass strategies! #redteam
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 22/07/2025
We are adding a binary injection vulnerability scanner to DarwinOps! -> A DarwinOps JXA template -> Scan for Injection vulnerabilities in binaries and Apps Vulnerable binaries could be abused to bypass EDR, hide a backdoor, access memory, or bypass TCC! #redteam
031
BallisKit @balliskit.bsky.social · 25/06/2025
Here is a reminder that a Powerful DotNET obfuscator is available in MacroPack. Assembly level obfuscation (or course). With the latest 2.7.5 it supports all your favorite #redteam DotNET tools! And tested on major EDRs :) blog.balliskit.com/obfuscation-...
blog.balliskit.com
Obfuscation and weaponization of .NET assemblies using MacroPack
For a couple of years now, .NET have been the go to language for a lot of famous offensive security tools like Rubeus, SeatBelt…
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 23/06/2025
MacOS security is very different from Windows. DarwinOps, our redteam tool targeting MacOS can help you tackle that issue! @antoineds.bsky.social just posted on our blog to help you understand the basics of initial access on MacOS with DarwinOps #redteam
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 06/06/2025
New tuto! Weaponize Mythic Apollo using MacroPack and ShellcodePack. Tested on EDRs of course. blog.balliskit.com/tutorial-myt... #redteam
blog.balliskit.com
Tutorial: Mythic Apollo with BallisKit MacroPack and ShellcodePack
Learn how to weaponize Mythic Apollo with BallisKit redteaming tools
031
BallisKit @balliskit.bsky.social · 27/05/2025
A new version of MacroPack Pro with improved DotNET obfuscator, new shellcode launcher, improved clickonce, and more will be released soon! Also, after Sliver, we a preparing tutorials with Mythic Apollo and Havoc 😎 #redteam
041
BallisKit @balliskit.bsky.social · 21/05/2025
Rubeus and Mythic Apollo DotNET Payload Obfuscation with MacroPack! This video demonstrates the next MacroPack Pro features: - DotNET obfuscation and evasion - EDR Bypass ready to use profiles - Compatibility with Mythic Apollo stager #redteam youtu.be/mzuT1MAQSXY
youtu.be
Rubeus and Mythic Apollo DotNET Payload Obfuscation with MacroPack
YouTube video by Sevagas
021
Reposted by BallisKit
BallisKit @balliskit.bsky.social · 06/05/2025
How to weaponize Sliver C2 and evade EDRs? With BallisKit ShellcodePack and MacroPack of course! Checkout this new tutorial on our blog! #redteam blog.balliskit.com/tutorial-sli...
blog.balliskit.com
Tutorial: Sliver C2 with BallisKit MacroPack and ShellcodePack
In this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam.
032
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 16/05/2025
DLL injection and DLL proxying on macOS? Yes it is possible! Checkout this blog by @antoineds.bsky.social about macOS automated DYLIB injection! blog.balliskit.com/macos-dylib-... #redteam
blog.balliskit.com
macOS DYLIB Injection at Scale: Designing a Self-Sufficient Loader
Let’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection)
021
BallisKit @balliskit.bsky.social · 06/05/2025
How to weaponize Sliver C2 and evade EDRs? With BallisKit ShellcodePack and MacroPack of course! Checkout this new tutorial on our blog! #redteam blog.balliskit.com/tutorial-sli...
blog.balliskit.com
Tutorial: Sliver C2 with BallisKit MacroPack and ShellcodePack
In this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam.
032
BallisKit @balliskit.bsky.social · 15/04/2025
Bypassing EDRs on MacOS can be a challenge. In our new blog post, @antoineds.bsky.social describes how EDRs leverage MacOS Network Extension to detect C2s and how to bypass this kind of detection using Mythic Apfell as an example. #redteam blog.balliskit.com/when-osascri...
blog.balliskit.com
When Osascript Goes Undetected: A Look at EDR Network Blind Spots
Discover how JXA subprocesses and custom network extensions can silently bypass macOS EDRs by evading audit and PID-based detection.
031
BallisKit @balliskit.bsky.social · 03/04/2025
For us, EDR bypass is not just a buzzword. MacroPack, ShellcodePack, and DarwinOps all come with bypass presets for major EDRs and Antivirus Those presets are regularly updated and tested! If you want to see a demo or an equivalent screenshot for the major EDRs contact us ! #redteam
032
BallisKit @balliskit.bsky.social · 20/03/2025
Balliskit Evasion Tip 🤖 To help with static analysis detection by EDR, ShellcodePack implements a method to load a shellcode from a separate file or from an URL This tutorial explains how to use that option! #redteam blog.balliskit.com/loading-a-sh...
blog.balliskit.com
Loading a shellcode from a file/URL with ShellcodePack
Shellcode in EXE files can sometimes be detected during static analysis, requiring various kinds of obfuscation to bypass EDRs. This…
032
BallisKit @balliskit.bsky.social · 06/03/2025
Redteaming on MacOS is hard... But BallisKit can help you! You can use DarwinOps to weaponize a Mythic C2 implant for MacOS and bypass EDRs! Checkout this blog Post by @antoinedss #redteam blog.balliskit.com/setup-and-we...
blog.balliskit.com
Setup and weaponize Mythic C2 using DarwinOps to target MacOS
We’ll look at how to set up Mythic C2 and its Apfell implant on MacOS. We will weaponize that implant to bypass EDRs using BallisKit…
031
BallisKit @balliskit.bsky.social · 03/03/2025
Obfuscate SharpHound? It's now possible with MacroPack. An version of MacroPack Pro was just released to improve our DotNET obfuscator! We now support packages build with tools like Costura! We tested we could obfuscate SharpHound, KrbRelay, and Mythic Apollo agent
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 17/02/2025
You need to run Rubeus, Seatbelt, or other .NET tool on an EDR protected machine? Well with the new version, MacroPack Pro is now also a powerful assembly obfuscation/weaponization tool ! 😎 We wrote a tutorial about that here: blog.balliskit.com/obfuscation-...
blog.balliskit.com
Obfuscation and weaponization of .NET assemblies using MacroPack
For a couple of years now, .NET have been the go to language for a lot of famous offensive security tools like Rubeus, SeatBelt…
032
BallisKit @balliskit.bsky.social · 13/02/2025
We updated our "DLL Hijacking with ShellcodePack" tutorial following the release of version 2.7.2 😎 blog.balliskit.com/dll-hijackin...
blog.balliskit.com
DLL Hijacking using ShellcodePack
Here is a little tutorial to perform some DLL Hijacking with BallisKit ShellcodePack (version 2.7.2 and above).
011
BallisKit @balliskit.bsky.social · 07/02/2025
Did you know ShellcodePack can be used to pack and weaponize third party exe, dll, .NET in addition to raw shellcodes? Example with Mimikatz! #redteam
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 23/01/2025
The video for my Advance Initial Access talk at Offensive X last year is available! #redteam Watch the talk here: youtu.be/bA2p27gQK4M?...
youtu.be
OFFENSIVEX Hacking Conference 2024 - Emeric Nasi
YouTube video by Offensive X
111
BallisKit @balliskit.bsky.social · 22/01/2025
Message for BallisKit customers! We are looking for customers who are willing to endorse us on our website. We often get asked about reference and it would be really helpful to show names. I know for some of you it's not possible but if you want to help please reach out it would really help us !
021
BallisKit @balliskit.bsky.social · 16/01/2025
Need initial access payloads for MacOS? Need help to bypass EDR on MacOS? Need undetected persistance on MacOS? Say no more and contact us about DarwinOps Our redteam ToolKit dedicated to MacOS! #redteam
021
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 07/01/2025
Many redteamers are used to Windows but have difficulties to address Mac OS. To help them, BallisKit released DarwinOps! This video demo: - Generation of malicious application - Code obfuscation - EDR Bypass ready to use profiles - Compatibility with C2 #redteam youtu.be/8B1UOLxuTgM
youtu.be
Redteam: Bypass EDR and deploy Mythic implant on MacOS using DarwinOps
YouTube video by Sevagas
041
BallisKit @balliskit.bsky.social · 30/12/2024
The next MacroPack will include a DotNET weaponization scenario! To obfuscate assemblies, and generate loaders in various languages. Ex: Turn Rubeus into a VBS or BAT file and call it with arguments as if it was the original file! Or just keep the EXE format if you prefer , but evade EDRs!
011
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 11/12/2024
Good News my RedTeam friends! New BallisKit tool to target MacOs: DarwinOps 😎 Features: - On shelf initial access scenarios - Multiple formats - Obfuscation methods and EDR bypass options - Privilege escalation and persistence - Compatible with several C2 #redteam
031
BallisKit @balliskit.bsky.social · 04/12/2024
BK Tip: MacroPack LNK generator supports multiple methods to launch payloads including dropping files, download-exec, run shellcode directly in memory! The LNK may be crafted use different lolbins and scripts polyglot properties! And yes, we tested on EDRs. #redteam
032
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 29/11/2024
The @balliskit.bsky.social team worked a lot the past weeks on a new project, expect big news in the coming days :)
011
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 25/11/2024
I am currently having a look at Defender reputation mechanism. I realized a few nice things I didn't know about. Still evaluating the potential for redteam other then dll sideloading with EXEs..
031
Reposted by BallisKit
Emeric Nasi @emericnasi.bsky.social · 16/11/2024
@Flangvik just released a very cool video showcasing ShellcodePack and MacroPack Pro against MDE. He demonstrates Python generation and dropping Python interpreter for initial access and assume breach. As well as bypass of MDE! #redteam www.youtube.com/watch?v=tz2w...
youtube.com
Bypassing Microsoft Defender for Endpoint with Balliskit
YouTube video by Flangvik
073