Sign in

FallenAngel666

@fallenangelc2.bsky.social
15 followers 22 following 33 posts

CRTL/CRTO/CRTP Researcher and enthusiast of EDR and Windows evasion fallenangel666-blog.pages.dev "Truly strong people are always gentle."

PostsRepliesMedia
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
Special thanks to @klezvirus.bsky.social for Moonwalk++ kept the original SystemFunction032 + static "MyTest1" key and the same VP(RWX) → ENCRYPT → VP(NOACCESS) ladder. Refs: github.com/klezVirus/Mo... / klezvirus.github.io/posts/Moonwa...
github.com
010
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
And the result is exactly what the technique promises: every WinHTTP call flies the encrypted circuit, WinDbg shows a clean 4-frame chain at WinHttpSendRequest while the code is unreadable (??), and check-in + tasking keep working.
100
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
I also self-hosted a MOV R15,RAX stash gadget in the unencrypted boundary page so the return value (session handles) survives the decrypt leg the original PoC never needed that because it ignores return values.
100
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
The tricky part: upstream encrypts its whole blob because the call arguments live outside it. Bahamut's API strings live in the image, so I encrypt the code region only, leaving the .rdata tail readable so the transport keeps working with the original encryption untouched.
100
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
the encryption handles memory inspection the two layers exactly as the original treats them.
100
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
Each call: VirtualProtect(RWX) → SystemFunction032 ENCRYPT → VirtualProtect(NOACCESS) → target. When it returns a ROP chain flips back to RWX, decrypts and restores protection. The spoofed chain handles stack inspection.
100
FallenAngel666 @fallenangelc2.bsky.social · 08/10/2026
I integrated Moonwalk++ into Bahamut: every WinHTTP call runs behind a spoofed caller chain while the agent's image is RC4-encrypted and PAGE_NOACCESS original SystemFunction032 + static "MyTest1" key. #RedTeam #windows #EDR #C2 #cybersecurity
110
FallenAngel666 @fallenangelc2.bsky.social · 27/09/2026
And special thanks to @5pider.net for recommending this technique to me Refs: github.com/susMdT/LoudS... dtsec.us/2023-09-15-S... #redteam #C2 #windows #EDR #CRTL
github.com
GitHub - susMdT/LoudSunRun: Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven
Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven - susMdT/LoudSunRun
000
FallenAngel666 @fallenangelc2.bsky.social · 27/09/2026
And I’ve really liked the result – to be honest, it works very well when it comes to injection; the only thing that has been tricky to implement is that I’ve had to discard the original Starburst worker profile and use a thread without fail for this implementation.
100
FallenAngel666 @fallenangelc2.bsky.social · 27/09/2026
the spoof addresses caller-chain inspection while the indirect syscalls address the return-address check, exactly as the original authors treat them as separate layers.
100
FallenAngel666 @fallenangelc2.bsky.social · 27/09/2026
I integrated LoudSunRun-style stack spoofing into Bahamut so direct API calls and indirect syscalls, which still execute from inside ntdll present a legitimate caller chain.
221
FallenAngel666 @fallenangelc2.bsky.social · 19/09/2026
Si, sin problema.
001
FallenAngel666 @fallenangelc2.bsky.social · 19/09/2026
Pues o una de dos. Ingeniería de telecomunicaciones (teleco de toda la vida) o Ingeniería de ciberseguridad.
100
FallenAngel666 @fallenangelc2.bsky.social · 19/09/2026
Zilean is working properly in Bahamut !!!! It’s been a good experiment with Sleepmask as a replacement for Ekko. What’s more, there’s no documentation on Zilean (I think my AI assistant has got the blues and my hands are aching). #redteam #UDRL #mythicc2 #cybersecurity #C2 #windows #EDR
020
Reposted by FallenAngel666
rajkit @rajkit.bsky.social · 15/09/2026
A serie of videos where going to increase the complexity of the compiled proyect from the simplest to hardest with JBKORE. @raphaelmudge.bsky.social www.youtube.com/watch?v=ibTm...
youtube.com
JBKORE ::: Example one ::: Simple http-to-stdout
YouTube video by JellyBee System
022
FallenAngel666 @fallenangelc2.bsky.social · 13/09/2026
Si, todo lo respeto a pavel me lo e leido (tengo el de windows kernel programing en mi biblioteca fisica). Yo ahora mismo estoy estudiando como hace las cosas 5spider para intentar "copiarle". Muchas gracias por el comentario y la ayuda.
210
Reposted by FallenAngel666
RastaMouse @rastamouse.me · 11/09/2026
Hopefully the talk is better than my mug shot… no promises though.
233
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
If you’ve got any implementation recommendations or criticisms of what I’m planning to implement, feel free to drop me a line (but please, be respectful). :') #redteam #MythicC2 #C2 #EDR #windows #cybersecurity #rooted
200
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
I don’t intend to publish it but Id like to share the things I’m adding, and above all I want to set myself the goal of presenting it at RootedCon 2027 in a talk. But well time will tell ( this year I’m really really busy as I’ve got my university entrance exams and Ive got loads of studying to do)
320
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
And ever since it came out, I’ve been analysing it and messing about a bit (whilst still spoiling my beloved Xenon). And finally, two months ago, I decided, ‘What if I used that as a basis to build my own agent?’ And well, the rest is history.
100
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
Then Starburst came out a Stardust-based agent from 5spider that made my head spin and made me go ‘wow’.
110
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
The first drafts of Bahamut worked, but it’s clear how inexperienced I am and that I haven’t programmed projects as serious as this one before (and no, AI doesn’t help in these cases – at best, it’s useful for an implementation or a POC).
100
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
Right then. I’ve finally got round to it. I’ve decided to start a rather ambitious project: to finish creating Bahamut. Bahamut is my personal custom agent for MythicC2, which focuses mainly on evading EDR/AV technologies.
170
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
If you have any implementation recommendations or criticism of what I’m planning to implement, feel free to write to me (but please be respectful). :') #redteam #EDR #MythicC2 #Crystalpalace #C2 #cybersecurity #windows
000
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
I don’t plan on publishing it, but I’d like to share the features I’m adding, and above all, I want to set a goal of presenting it at RootedCon 2027 in a talk. But time will tell (plus, this year I’m really, really busy—I’ve been accepted to college and have to study a lot).
100
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
Ever since it came out, I’ve been analyzing it and messing around with it a bit (while still pampering my beloved Xenon). And finally, two months ago, I decided, “What if I use that foundation to build my own agent?” And well, the rest is history.
100
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
Then Starburst came out—an agent based on 5spider’s Stardust—that made my head spin and made me say, “Wow.”
100
FallenAngel666 @fallenangelc2.bsky.social · 11/09/2026
The first drafts of Bahamut worked, but it’s clear how inexperienced I am and that I haven’t programmed projects as serious as this one before (and no, AI doesn’t help in these cases—at most, it’s useful for an implementation or a POC).
100
Reposted by FallenAngel666
RastaMouse @rastamouse.me · 19/08/2026
@raphaelmudge.bsky.social github.com/sliverarmory...
github.com
GitHub - sliverarmory/crystal-grotto: Golang Port of Crystal Palace
Golang Port of Crystal Palace. Contribute to sliverarmory/crystal-grotto development by creating an account on GitHub.
153
FallenAngel666 @fallenangelc2.bsky.social · 07/08/2026
This concludes the trilogy of documentation on Crystal Palace applied to Mythic. This one is the weakest of the three. Maybe I'll have something new to share soon :)
000
FallenAngel666 @fallenangelc2.bsky.social · 07/08/2026
This time I wanted to try an experiment with Rust instead of C :)
000
FallenAngel666 @fallenangelc2.bsky.social · 07/08/2026
My latest research/documentation has now been published. This is the weakest of the three because it only explains how I develop my loaders for my Mythic and Crystal Palace shellcodes. (As I always mention, this is in Spanish.) fallenangel666-blog.pages.dev/posts/loader... #RedTeam #EDR #C2 #C++
fallenangel666-blog.pages.dev
Un cargador Stage-0 en Rust para Crystal Palace PICOs | Fuck the critics
Estaba harto de escribir VirtualAlloc → WriteProcessMemory → CreateRemoteThread en cada stage y de ver cómo las mismas reglas YARA lo detectaban cada vez. Así q
240
FallenAngel666 @fallenangelc2.bsky.social · 06/08/2026
And when will you have ducks? I like ducks. 🦆
100
Reposted by FallenAngel666
RastaMouse @rastamouse.me · 28/07/2026
I wrote a little bit about COFF Mixing rastamouse.me/coff-mixing/
284
FallenAngel666 @fallenangelc2.bsky.social · 25/07/2026
The documents are quite technical, just like my previous work. And generally speaking, the vast majority of people who have read them have liked them. As always, I'm open to any kind of feedback, as long as it's respectful.
000
FallenAngel666 @fallenangelc2.bsky.social · 25/07/2026
They provide a very detailed explanation of how Crystal Palace works and how I use it to bypass EDRs. As I said, I just created my account and simply wanted to share them here :) (P.S.: They’re written in Spanish I like things to be in Spanish, which is my language.)
100
FallenAngel666 @fallenangelc2.bsky.social · 25/07/2026
Hi, bluesky. I just created my account. And I wanted to share two of my most recent posts here about Crystal Palace and Mythic. fallenangel666-blog.pages.dev/posts/crysta... fallenangel666-blog.pages.dev/posts/mythic...
fallenangel666-blog.pages.dev
crystal-palace. tradecraft link PIC y evasion de EDRs | Fuck the critics
Esto no es un tutorial. Ya existen muchos. Esto es una inmersión arquitectónica profunda en Crystal Palace, el linker PIC y el lenguaje de script de enlazado cr
162