BallisKit @balliskit.bsky.social · 29/09/2026Need to pivot through a macOS target during a Red Team operation? 🍎 Mirage C2 includes built-in SOCKS proxying, letting operators route traffic through a compromised Mac and reach resources beyond the initial foothold. Start it. Pivot. Keep moving. Part of DarwinOps by BallisKit. #RedTeam #macOS 011
BallisKit @balliskit.bsky.social · 18/09/2026Introducing Mirage C2 🥷 — our new modular, in-memory macOS implant for DarwinOps. Shell, SOCKS proxy, secret extraction + private techniques for process injection, privilege escalation, TCC bypass & persistence. The full macOS attack chain, from initial access to post-exploitation. #redteam 012
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 08/09/2026Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion, private .NET obfuscator and initial access ! We also started to integrate exploits for vulnerabilities abused in the wild! #redteam 021
BallisKit @balliskit.bsky.social · 18/08/2026The new BallisKit tool soon to be released, an advanced macOS Mythic implant! All modular, in memory execution, includes private methods for process injection, TCC bypass, secret grabbing, persistance, malware behavior emulation, EDR Evasion, socks proxy, and more! #redteam #mirage 031
BallisKit @balliskit.bsky.social · 23/07/2026Learn how to Weaponize Adaptix C2 with MacroPack and ShellcodePack! -> EXE and DLL Sideloading examples -> LNK spoofing PDF, HTA, Clickonce, etc. -> EDR Evasion options #redteam blog.balliskit.com/tutorial-ada...blog.balliskit.comTutorial: Adaptix C2 with ShellcodePack and MacroPackAdaptix C2 is a powerful and popular open source C2 framework. Adaptix gitbook can be found here. Sources are available on Adaptix C2… 111
BallisKit @balliskit.bsky.social · 20/05/2026We updated our Sliver C2 + BallisKit tutorial to adapt to the latest Sliver version. Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads! More C2 tutorials available on the blog (Adaptix, Mythic) blog.balliskit.com/tutorial-sli...blog.balliskit.comTutorial: Sliver C2 with BallisKit MacroPack and ShellcodePackIn this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam. 033
BallisKit @balliskit.bsky.social · 15/04/2026New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events! #redteam 011
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 07/04/2026I just wrote a tutorial explaining how to combine Adaptix C2 with MacroPack and ShellcodePack! This provides multiple initial access and EDR evasion options to Adaptix C2 users. Tutorial includes: LNK, CLickOnce, DLL Sideloading, Exe, HTA, etc! #redteam blog.balliskit.com/tutorial-ada...blog.balliskit.comTutorial: Adaptix C2 with ShellcodePack and MacroPackAdaptix C2 is a powerful and popular open source C2 framework. Adaptix gitbook can be found here. Sources are available on Adaptix C2… 011
BallisKit @balliskit.bsky.social · 18/03/2026BallisKit ShellcodePack 2.8.1 is out! Focus: AppDomain injection & DLL sideloading, plus updated EDR evasion profiles. Learn how to backdoor .NET apps with our tutorial: blog.balliskit.com/appdomain-in... #redteamblog.balliskit.comAppDomain Injection -Backdooring .NET Framework ApplicationsAppDomain Injection is a technique that allows you to execute arbitrary code within .NET Framework applications by hijacking the AppDomain… 021
BallisKit @balliskit.bsky.social · 03/02/2026MacroPack new version is out! 🥳 With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario! Also now everything can be leveraged with the new BallisKit GUI! 😎 #redteam 011
BallisKit @balliskit.bsky.social · 22/01/2026DarwinOps just leveled up 🚀 Now supports AppleScript (SCPT), a format actively abused for macOS phishing. Plus new Ruby, VSCode , NPM & Homebrew payloads. A true macOS red team Swiss Army knife. AppleScript initial access guide 👇 blog.balliskit.com/macos-redtea...blog.balliskit.comMacOS Redteam 4: Initial Access with AppleScriptMacOS is often considered well protected, largely due to Gatekeeper. However, some execution vectors still operate under a different trust… 011
BallisKit @balliskit.bsky.social · 07/01/2026Tutorial: DLL Sideloading and function proxying with ShellcodePack BallisKit ShellcodePack version 2.8.0 is available! This version comes with a new GUI, EDR evasion methods as well as enhanced DLL sideloading/hijacking. You can find the tutorial here: blog.balliskit.com/tutorial-dll...blog.balliskit.comTutorial: DLL Sideloading and function proxying with ShellcodePackDLL sideloading is a technique that allows an attacker to have a legitimate signed application run some malicious code on Windows. It work… 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 20/11/2025PKG is a kind of MacOS MSI equivalent. It's also used as an initial access payload! Read how DarwinOps can be used to generate PKG for redteams. We also included a method to run the PKG without admin privileges -> Reduced number of clicks! #redteam blog.balliskit.com/macos-redtea...blog.balliskit.comMacOS Redteam 3: Initial Access with DarwinOps PKGState of the art: 021
BallisKit @balliskit.bsky.social · 19/11/2025We are preparing a new version of ShellcodePack! -> Automated and improved DLL sideloading/proxying capacity -> AppDomain injection -> New Responsive GUI! -> Many more new features And of course up to date EDR evasion :) #shellcodepack 021
BallisKit @balliskit.bsky.social · 14/10/2025MacroPack v2.8.7 is out! New GUI & updated EDR evasion! New features include Advanced LNK spoofing, expanded .NET obfuscation, and ML-evasion. For authorized red-team use! #RedTeam #offensivesecurity 032
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 02/10/2025MacOS red-team made practical — Objective-C implant for DarwinOps! Private Mythic C2 implant: lightweight (in-memory shellcode), post-exploitation, EDR & MDM evasion, integrates with DarwinOps + GateKeeper bypass. Contact us for more details! #RedTeam #macOS 022
BallisKit @balliskit.bsky.social · 24/09/2025The next version of MacroPack is going to be huge! A new GUI, updated EDR bypass profiles, new evasion options, and many other things :) #redteam 011
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 17/09/2025Binary injection vulnerabilities can be found in many MacOS apps. Those may be abused to bypass EDR, hide backdoor, access memory, or bypass TCC! DarwinOps provides - An advanced injection vulnerability scanner - A redteam scenario to exploit them #redteam blog.balliskit.com/macos-dylib-...blog.balliskit.commacOS DYLIB Injection at Scale: Designing a Self-Sufficient LoaderLet’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection) 042
BallisKit @balliskit.bsky.social · 08/09/2025ShellcodePack 2.7.5 is now available! It includes updated bypass profiles for major EDRs We also improved: - ML detection evasion - ETW Patch - CallStack Spoofing ShellcodePack can be used to weaponize any raw shellcode or PE including DotNET, Go, and Rust :) #redteam 031
BallisKit @balliskit.bsky.social · 14/08/2025Initial Access on MacOS made easy ! DarwinOps now supports DMG phishing profiles! Those are on shelf realistic templates with Gatekeeper bypass techniques :) This version also introduce a binary injection vulnerability scanner for MacOS! #redteam 021
BallisKit @balliskit.bsky.social · 01/08/2025MacOS DMG phishing templates are coming in the next DarwinOps release! Ready to use, configurable, and with new GateKeeper bypass strategies! #redteam 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 22/07/2025We are adding a binary injection vulnerability scanner to DarwinOps! -> A DarwinOps JXA template -> Scan for Injection vulnerabilities in binaries and Apps Vulnerable binaries could be abused to bypass EDR, hide a backdoor, access memory, or bypass TCC! #redteam 031
BallisKit @balliskit.bsky.social · 25/06/2025Here is a reminder that a Powerful DotNET obfuscator is available in MacroPack. Assembly level obfuscation (or course). With the latest 2.7.5 it supports all your favorite #redteam DotNET tools! And tested on major EDRs :) blog.balliskit.com/obfuscation-...blog.balliskit.comObfuscation and weaponization of .NET assemblies using MacroPackFor a couple of years now, .NET have been the go to language for a lot of famous offensive security tools like Rubeus, SeatBelt… 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 23/06/2025MacOS security is very different from Windows. DarwinOps, our redteam tool targeting MacOS can help you tackle that issue! @antoineds.bsky.social just posted on our blog to help you understand the basics of initial access on MacOS with DarwinOps #redteam 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 06/06/2025New tuto! Weaponize Mythic Apollo using MacroPack and ShellcodePack. Tested on EDRs of course. blog.balliskit.com/tutorial-myt... #redteamblog.balliskit.comTutorial: Mythic Apollo with BallisKit MacroPack and ShellcodePackLearn how to weaponize Mythic Apollo with BallisKit redteaming tools 031
BallisKit @balliskit.bsky.social · 27/05/2025A new version of MacroPack Pro with improved DotNET obfuscator, new shellcode launcher, improved clickonce, and more will be released soon! Also, after Sliver, we a preparing tutorials with Mythic Apollo and Havoc 😎 #redteam 041
BallisKit @balliskit.bsky.social · 21/05/2025Rubeus and Mythic Apollo DotNET Payload Obfuscation with MacroPack! This video demonstrates the next MacroPack Pro features: - DotNET obfuscation and evasion - EDR Bypass ready to use profiles - Compatibility with Mythic Apollo stager #redteam youtu.be/mzuT1MAQSXYyoutu.beRubeus and Mythic Apollo DotNET Payload Obfuscation with MacroPackYouTube video by Sevagas 021
Reposted by BallisKitBallisKit @balliskit.bsky.social · 06/05/2025How to weaponize Sliver C2 and evade EDRs? With BallisKit ShellcodePack and MacroPack of course! Checkout this new tutorial on our blog! #redteam blog.balliskit.com/tutorial-sli...blog.balliskit.comTutorial: Sliver C2 with BallisKit MacroPack and ShellcodePackIn this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam. 032
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 16/05/2025DLL injection and DLL proxying on macOS? Yes it is possible! Checkout this blog by @antoineds.bsky.social about macOS automated DYLIB injection! blog.balliskit.com/macos-dylib-... #redteamblog.balliskit.commacOS DYLIB Injection at Scale: Designing a Self-Sufficient LoaderLet’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection) 021
BallisKit @balliskit.bsky.social · 06/05/2025How to weaponize Sliver C2 and evade EDRs? With BallisKit ShellcodePack and MacroPack of course! Checkout this new tutorial on our blog! #redteam blog.balliskit.com/tutorial-sli...blog.balliskit.comTutorial: Sliver C2 with BallisKit MacroPack and ShellcodePackIn this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam. 032
BallisKit @balliskit.bsky.social · 15/04/2025Bypassing EDRs on MacOS can be a challenge. In our new blog post, @antoineds.bsky.social describes how EDRs leverage MacOS Network Extension to detect C2s and how to bypass this kind of detection using Mythic Apfell as an example. #redteam blog.balliskit.com/when-osascri...blog.balliskit.comWhen Osascript Goes Undetected: A Look at EDR Network Blind SpotsDiscover how JXA subprocesses and custom network extensions can silently bypass macOS EDRs by evading audit and PID-based detection. 031
BallisKit @balliskit.bsky.social · 03/04/2025For us, EDR bypass is not just a buzzword. MacroPack, ShellcodePack, and DarwinOps all come with bypass presets for major EDRs and Antivirus Those presets are regularly updated and tested! If you want to see a demo or an equivalent screenshot for the major EDRs contact us ! #redteam 032
BallisKit @balliskit.bsky.social · 20/03/2025Balliskit Evasion Tip 🤖 To help with static analysis detection by EDR, ShellcodePack implements a method to load a shellcode from a separate file or from an URL This tutorial explains how to use that option! #redteam blog.balliskit.com/loading-a-sh...blog.balliskit.comLoading a shellcode from a file/URL with ShellcodePackShellcode in EXE files can sometimes be detected during static analysis, requiring various kinds of obfuscation to bypass EDRs. This… 032
BallisKit @balliskit.bsky.social · 06/03/2025Redteaming on MacOS is hard... But BallisKit can help you! You can use DarwinOps to weaponize a Mythic C2 implant for MacOS and bypass EDRs! Checkout this blog Post by @antoinedss #redteam blog.balliskit.com/setup-and-we...blog.balliskit.comSetup and weaponize Mythic C2 using DarwinOps to target MacOSWe’ll look at how to set up Mythic C2 and its Apfell implant on MacOS. We will weaponize that implant to bypass EDRs using BallisKit… 031
BallisKit @balliskit.bsky.social · 03/03/2025Obfuscate SharpHound? It's now possible with MacroPack. An version of MacroPack Pro was just released to improve our DotNET obfuscator! We now support packages build with tools like Costura! We tested we could obfuscate SharpHound, KrbRelay, and Mythic Apollo agent 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 17/02/2025You need to run Rubeus, Seatbelt, or other .NET tool on an EDR protected machine? Well with the new version, MacroPack Pro is now also a powerful assembly obfuscation/weaponization tool ! 😎 We wrote a tutorial about that here: blog.balliskit.com/obfuscation-...blog.balliskit.comObfuscation and weaponization of .NET assemblies using MacroPackFor a couple of years now, .NET have been the go to language for a lot of famous offensive security tools like Rubeus, SeatBelt… 032
BallisKit @balliskit.bsky.social · 13/02/2025We updated our "DLL Hijacking with ShellcodePack" tutorial following the release of version 2.7.2 😎 blog.balliskit.com/dll-hijackin...blog.balliskit.comDLL Hijacking using ShellcodePackHere is a little tutorial to perform some DLL Hijacking with BallisKit ShellcodePack (version 2.7.2 and above). 011
BallisKit @balliskit.bsky.social · 07/02/2025Did you know ShellcodePack can be used to pack and weaponize third party exe, dll, .NET in addition to raw shellcodes? Example with Mimikatz! #redteam 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 23/01/2025The video for my Advance Initial Access talk at Offensive X last year is available! #redteam Watch the talk here: youtu.be/bA2p27gQK4M?...youtu.beOFFENSIVEX Hacking Conference 2024 - Emeric NasiYouTube video by Offensive X 111
BallisKit @balliskit.bsky.social · 22/01/2025Message for BallisKit customers! We are looking for customers who are willing to endorse us on our website. We often get asked about reference and it would be really helpful to show names. I know for some of you it's not possible but if you want to help please reach out it would really help us ! 021
BallisKit @balliskit.bsky.social · 16/01/2025Need initial access payloads for MacOS? Need help to bypass EDR on MacOS? Need undetected persistance on MacOS? Say no more and contact us about DarwinOps Our redteam ToolKit dedicated to MacOS! #redteam 021
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 07/01/2025Many redteamers are used to Windows but have difficulties to address Mac OS. To help them, BallisKit released DarwinOps! This video demo: - Generation of malicious application - Code obfuscation - EDR Bypass ready to use profiles - Compatibility with C2 #redteam youtu.be/8B1UOLxuTgMyoutu.beRedteam: Bypass EDR and deploy Mythic implant on MacOS using DarwinOpsYouTube video by Sevagas 041
BallisKit @balliskit.bsky.social · 30/12/2024The next MacroPack will include a DotNET weaponization scenario! To obfuscate assemblies, and generate loaders in various languages. Ex: Turn Rubeus into a VBS or BAT file and call it with arguments as if it was the original file! Or just keep the EXE format if you prefer , but evade EDRs! 011
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 11/12/2024Good News my RedTeam friends! New BallisKit tool to target MacOs: DarwinOps 😎 Features: - On shelf initial access scenarios - Multiple formats - Obfuscation methods and EDR bypass options - Privilege escalation and persistence - Compatible with several C2 #redteam 031
BallisKit @balliskit.bsky.social · 04/12/2024BK Tip: MacroPack LNK generator supports multiple methods to launch payloads including dropping files, download-exec, run shellcode directly in memory! The LNK may be crafted use different lolbins and scripts polyglot properties! And yes, we tested on EDRs. #redteam 032
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 29/11/2024The @balliskit.bsky.social team worked a lot the past weeks on a new project, expect big news in the coming days :) 011
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 25/11/2024I am currently having a look at Defender reputation mechanism. I realized a few nice things I didn't know about. Still evaluating the potential for redteam other then dll sideloading with EXEs.. 031
Reposted by BallisKitEmeric Nasi @emericnasi.bsky.social · 16/11/2024@Flangvik just released a very cool video showcasing ShellcodePack and MacroPack Pro against MDE. He demonstrates Python generation and dropping Python interpreter for initial access and assume breach. As well as bypass of MDE! #redteam www.youtube.com/watch?v=tz2w...youtube.comBypassing Microsoft Defender for Endpoint with BalliskitYouTube video by Flangvik 073