Sign in

Calzone

@calz0n3.bsky.social
62 followers 93 following 41 posts

sorry, computer please.donothack.us github.com/ofasgard

PostsRepliesMedia
Calzone @calz0n3.bsky.social · 26/07/2026
bof2pico: Simple helper utility for converting BOFs into PICOs (with hardcoded arguments) that celebi knows how to understand. github.com/ofasgard/cel... Thanks to @rastamouse.me for the suggestion to include a format specifier with the arguments!
062
Reposted by Calzone
Bingus @sizeable-bingus.bsky.social · 14/07/2026
New post about a CET compatible stack spoofing technique and a loader integrating it :) bigbingus.com/posts/bingus... github.com/Sizeable-Bin...
bigbingus.com
BingusLdr: CET Compatible Stack Spoofing | bigbingus.com
BingusLdr: CET Compatible Stack Spoofing
175
Calzone @calz0n3.bsky.social · 23/07/2026
Got a little bof2pico tool working (based on @raphaelmudge.bsky.social's "Simple BOF Runner") to convert BOFs into PICOs that celebi knows how to execute :) parsing arbitrary argument datatypes into the BOF argument format is a little more challenging, though.
Screenshot demonstrating the TrustedSec sc_stop BOF running as a PICO!
152
Reposted by Calzone
k1ng0fn0th1ng.bsky.social @k1ng0fn0th1ng.bsky.social · 06/05/2026
I've published CrystalForge, a Crystal Palace-based project that brings custom Crystal Palace loaders into AdaptixC2. Provide a .spec file, and the agent plugin handles the intermediate DLL linking and shellcode generation. github.com/k1ng0fn0th1n...
071
Calzone @calz0n3.bsky.social · 29/04/2026
Taking a break from other projects, so just a small one for now: I made a little proof-of-concept HTML smuggling implementation using Rust's web assembly support: github.com/ofasgard/smu...
github.com
GitHub - ofasgard/smuggle-rs: PoC for WASM HTML smuggling, written in Rust.
PoC for WASM HTML smuggling, written in Rust. Contribute to ofasgard/smuggle-rs development by creating an account on GitHub.
194
Reposted by Calzone
Nell Gwyn @ne11gwyn.bsky.social · 25/04/2026
A photo showing an electric road sign having suffered a Windows error, solid blue with a white ":(" off-center, as part of a zoomed-in Windows error screen. Above the pole with the sign on it is a flat gray sky due to it being overcast.

Tumblr user jellyfishdirigible has captioned this photo:
The sky above the television tuned to a dead channel was the color of a different, much older television tuned to a dead channel
92736750
Reposted by Calzone
Raphael Mudge @raphaelmudge.bsky.social · 21/04/2026
I did some garden tending: Updated the TCG community pavilion. Added some projects and posts. Re-organized the projects section. I also added a note about ground truth curation vs. provenance for red team use. Something I wrestled with/put some thought into. tradecraftgarden.org/references.h...
063
Reposted by Calzone
Eli Mallon @iame.li · 15/04/2026
Every shell and terminal emulator ever with 100% confidence that they're doing the right thing for the user: ^[[A^[[A^[[A^[[A^[[A^[[A^[[A
922825
Reposted by Calzone
David Buchanan @retr0.id · 31/03/2026
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
262845850
Reposted by Calzone
Raphael Mudge @raphaelmudge.bsky.social · 28/03/2026
If you're a C2 engineer, I encourage you to watch @rastamouse.me 's expanding Crystal C2 docs. It's a World-of-tomorrow exhibit for what C2 architecture could be. Use-time capability composition, radical instrumentation opportunity, & reducing agent's burden rasta-mouse.gitbook.io/crystalc2/do...
rasta-mouse.gitbook.io
Welcome | Documentation | CrystalC2
1102
Reposted by Calzone
Raphael Mudge @raphaelmudge.bsky.social · 15/03/2026
Bypassing EDR in a Crystal Clear Way by x.com/LorenzoMeacci Blog: lorenzomeacci.com/bypassing-ed... Project: github.com/kapla0011/Ka...
lorenzomeacci.com
Bypassing EDR in a Crystal Clear Way | Lorenzo Meacci
Most operators spend days engineering the perfect shellcode loader and ship the payload naked. This blog takes you from how C2 payloads actually work under the hood all the way to building a fully eva...
072
Calzone @calz0n3.bsky.social · 12/03/2026
Got dynamic PICO upload and execution working on Celebi :) both agent and uploaded capability are all written in pure Crystal Palace C, which means this is now starting to vaguely resemble a usable (though opsec-unsafe) implant!
First screenshot, displaying the Mythic UI. The register and execute_pico command have been used to upload a PICO, then execute it.Second screenshot, showing the debug console on the target machine. It displays logs of a successful file upload and PICO execution.Third screenshot, displaying the PICO actually executing. A messagebox has popped up onscreen.
260
Calzone @calz0n3.bsky.social · 11/03/2026
Hello prospective employer, I have various useful skills such as: - write malware - eat hot chip - lie Wait, where are you going?
010
Reposted by Calzone
Almond Offsec @almondoffsec.bsky.social · 10/03/2026
Are one-way trusts really one way? @lowercasedrm.bsky.social sums up how the TDO password lets you turn a one-way AD forest trust into bidirectional access, and releases a new tool to remotely extract these secrets. offsec.almond.consulting/trust-no-one...
032
Calzone @calz0n3.bsky.social · 08/03/2026
Still very much an early WIP, but the Crystal Palace-based Mythic agent I'm working on can be found here: github.com/ofasgard/cel...
github.com
GitHub - ofasgard/celebi: A WIP Mythic agent that uses Crystal Palace to build its payloads.
A WIP Mythic agent that uses Crystal Palace to build its payloads. - ofasgard/celebi
232
Reposted by Calzone
Alice Averlong 🏳️‍⚧️ @alice.averlong.com · 06/03/2026
Hiya! Anyone in the SF Bay Area/Remote need a cool programmer for your team? I've been messing with computers for over 30 years now, I can program anything with bits, and I've got a lot of experience with all sorts of different systems, environments, and languages. wiki.averlong.com/My_Resume
wiki.averlong.com
My Resume - Alice Averlong Wiki
7358191
Calzone @calz0n3.bsky.social · 28/02/2026
Started working on a Mythic agent that uses Crystal Palace to generate its shellcode. So far I've just got it to emit some generic shellcode - it doesn't talk to Mythic yet. I'm hoping to make a fully modular agent that you can patch your tradecraft into when you generate a payload :)
Screenshot demonstrating some Crystal Palace shellcode generated by Mythic, running on a Windows machine and popping a message box.Screenshot demonstrating the payload UUID from a Mythic payload, patched into a Crystal Palace linker variable.
122
Calzone @calz0n3.bsky.social · 11/02/2026
If your lab environment doesn't have a dumb theme, what's even the point?
Two virtual machines in a testing lab, with wallpapers and names based on characters from Over the Garden Wall
010
Reposted by Calzone
Mallory Moore @sexabolition.blog · 06/02/2026
If Minnesota soccer moms in signal chats can figure out compartmentalization and redundancy so can fucking IoT vendors
1383
Reposted by Calzone
Raphael Mudge @raphaelmudge.bsky.social · 02/02/2026
The Islands of Invariance More than I ever thought I'd write about Yara signatures. Oh also, Crystal Palace has a Yara rule generator too. aff-wg.org/2026/02/02/t...
aff-wg.org
The Islands of Invariance
Crystal Palace now has a Yara rule generator. In this blog post, I’ll walk you through the design and evaluation of this feature. rule PageStream_rDLL_03495de1 { meta: description = “PageStre…
073
Reposted by Calzone
Amos @amosduveen.bsky.social · 02/02/2026
This pretty much nails what underlies all the hype about sentient AIs.
14217
Reposted by Calzone
Raphael Mudge @raphaelmudge.bsky.social · 23/01/2026
Cobalt Strike blog ppost by x.com/joehowwolf on using Crystal Palace to mash-up Page Streaming and Draugr Call Stack Spoofing into a Cobalt Strike UDRL. (Again, I really love the comics. They are perfect).
192
Reposted by Calzone
Lesley Carhart @hacks4pancakes.com · 16/01/2026
-hacks4pancakes- • 1d
The reason the good faith seniors on here are posting that the junior / mid level market is bad (it is) is because we have watched it crash in real time and a lotta of us are dealing with serious fallout as both hiring managers or mentors.
It's genuinely a good faith warning. It's not like, "don't get into the field we love". It's just that for a really long time you could get into cybersecurity with no degree and no IT experience because the demand was so high. And schools, influencers, and parents still play it off that it's like that. That people can work full time remote and make 80k entry salary.
It's not. It hasn't been for a couple years. We've been hit by "professionalizing" and oversaturation of graduates. Can you still get in with a sec+, a kali box and a dream? Maybe, if you really meet the right people and get lucky.
Pragmatically though, that won't be the case for 99.9% of young people now, and if we care at all we need to counter the "everything is rosy" message people are using to sell boot camps. We are getting hundreds of cybersecurity grads and laid off professionals with work rights applying for positions.
How can organizations even take the time to look beyond that at hundreds more juniors with no degree, criminal convictions, a GED, needing a' v sponsor, etc?You really need to take it seriously and make yourself a top candidate. And these days to be competitive you typically need a bachelors, certs, and some hands on IT work experience. You need a very good professional network.
That's not true of every case. People will get lucky.
Or they'll have a security clearance or live in the right remote place for an in person only job. It happens.
Not often. The best thing we can do is try to enforce that they need to work seriously hard and have solid professional credentials.
TLDR we aren't all assholes; some of us are trying to save 20yos from falling for Uncle Bob putting them in a bootcamp to make an easy six figures.
1010338
Reposted by Calzone
Caravelle @caravellin.bsky.social · 17/12/2025
low erth orbit perfec t size for put datacenter in to n\ap! outside very Soft and Comfort datacenter hum soundly in Low Earth Orbit. Put Datacenter in Low Earth Orbit. no problems ever in low earth orbbt because good Temperature and Sun exposure for datacenter hot of radiation.
1164
Calzone @calz0n3.bsky.social · 05/12/2025
Is it cursed to pass arguments to the assembly in execute-assembly-pico using the linker variables introduced in the new Crystal Palace?
It's a screenshot of a linker spec for Crystal Palace. The screenshot depicts the argument-passing setup described in the post. The screenshot menaces with bands of tourmaline.
010
Calzone @calz0n3.bsky.social · 03/12/2025
My PICOs and unit testing library have been updated for the newest version of Crystal Palace and LibTCG :)
011
Calzone @calz0n3.bsky.social · 03/12/2025
Nothing like a two-week holiday to completely kill your momentum on all of your projects! Not that I'm complaining... but how do I write assembly again? 🤔
010
Calzone @calz0n3.bsky.social · 21/10/2025
LibCPLTest: A shared library for Crystal Palace that allows you to unit test your PICOs. It's nothing too fancy, just a few helper functions and a macro, but it's helped me to create a consistent framework for testing my PIC capabilities. github.com/ofasgard/Lib...
github.com
GitHub - ofasgard/LibCPLTest: A shared library for Crystal Palace that allows you to unit test your PICOs.
A shared library for Crystal Palace that allows you to unit test your PICOs. - ofasgard/LibCPLTest
023
Calzone @calz0n3.bsky.social · 20/10/2025
There are two wolves inside of me. One is a grotty little hacker that wants to make stuff that barely works, and the other is a software dev who wants to do ✨Test Driven Development✨
130
Calzone @calz0n3.bsky.social · 20/10/2025
I don't think the ecosystem is quite there yet, but I feel like we're so close to being able to perform fully automated fuzzing of modular tradecraft vs. EDR detections using Crystal Palace...
100
Calzone @calz0n3.bsky.social · 16/10/2025
Working on a new PICO! This one is an in-memory CLR hoster that uses the same technique as execute-assembly/donut to invoke a .NET assembly without touching the disk.
A screenshot of a Crystal Palace PICO running. It's invoking a .NET assembly, specifically Rubeus.
251
Calzone @calz0n3.bsky.social · 14/10/2025
The new Crystal Palace version is very cool. Having DFR in your PIC code and just providing a resolver function is so much more ergonomic than having two different mechanisms for resolving APIs! I love it - already updated my HWB PICO to incorporate the new functionality.
022
Reposted by Calzone
Sean T. Collins @seantcollins.com · 06/10/2025
CHATGPT: I understand where you're coming from. You worked really hard to get here, and now it's time to enjoy the fruit of your labors. ISILDUR: So I should keep it? Elrond says I shouldn't CHATGPT: The ring is precious. Sometimes friends don't have your best interests at heart. ISILDUR: true
39107933056
Calzone @calz0n3.bsky.social · 29/09/2025
I've been obsessed with @raphaelmudge.bsky.social 's Crystal Palace since I learned about it at Beacon earlier this month, so... here's a WIP PICO I wrote to hook functions with hardware breakpoints 👀 github.com/ofasgard/har...
github.com
GitHub - ofasgard/hardware-breakpoint-pico: A PICO for Crystal Palace that implements hardware breakpoint hooking.
A PICO for Crystal Palace that implements hardware breakpoint hooking. - ofasgard/hardware-breakpoint-pico
061