Sign in

netbiosX

@netbiosx.bsky.social
1.9K followers 83 following 353 posts

Purple Team

PostsRepliesMedia
netbiosX @netbiosx.bsky.social · 24/09/2026
projectblack.io
Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
010
netbiosX @netbiosx.bsky.social · 22/09/2026
🎙️ The dump encoding library (𝑾𝒆𝒓𝑬𝒏𝒄.𝒅𝒍𝒍) enables threat actors to adopt the encryption used by Microsoft in their implant. Dropping a short video: 1️⃣ Encryption of payload (calc.bin) using the Microsoft 𝑾𝒆𝒓𝑬𝒏𝒄.𝒅𝒍𝒍 library (part of Windows 10 and 11) 2️⃣ Decryption with a Private Key and Execution
000
netbiosX @netbiosx.bsky.social · 21/09/2026
🚨 Implant Encryption via the Microsoft Dump Encoding Library 𝑫𝒆𝒕𝒆𝒄𝒕𝒊𝒐𝒏 𝑺𝒕𝒓𝒂𝒕𝒆𝒈𝒊𝒆𝒔 ✅️ Image Load of WerEnc.dll by arbitrary Processes - Event ID 7 (Sysmon) ✅️ File Creation - Event ID 11 (Sysmon) ✅️ Network Connection - Event ID 3 (Sysmon) ✒️ ipurple.team/2026/09/21/d...
ipurple.team
Dump Encoding Library
The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
000
netbiosX @netbiosx.bsky.social · 16/09/2026
When I started ipurple.team two years ago, my goal was to give SOC teams practical detection opportunities across some of the most modern adversarial techniques. So far, I’ve documented 25 techniques, and every article includes: ✅ SIGMA Rules ✅ Sysmon Configs ✅ Threat Hunting Queries
020
netbiosX @netbiosx.bsky.social · 14/09/2026
Claude: Executing code by using a math calculation from a project session.
020
netbiosX @netbiosx.bsky.social · 14/09/2026
A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel
github.com
GitHub - Whispergate/msteams: Mythic C2 MSTeams Communication Channel
Mythic C2 MSTeams Communication Channel. Contribute to Whispergate/msteams development by creating an account on GitHub.
030
netbiosX @netbiosx.bsky.social · 13/09/2026
Another day, another experiment playing with MCP and Codex to execute code.
012
netbiosX @netbiosx.bsky.social · 11/09/2026
There are two additional LOLBins capable of executing code that are part of the .NET ecosystem.
021
netbiosX @netbiosx.bsky.social · 09/09/2026
Disable Windows Defender via Antivirus Fake Registration
ipurple.team
Windows Security Center
The Windows Security Center collects and presents information about the status of the antivirus control (Windows Defender or 3rd party). When a third-party antivirus is installed, Windows Defender …
011
netbiosX @netbiosx.bsky.social · 27/08/2026
If you’re hunting for malicious .tt files (msbuild), follow the approach below to detect: ✅ 𝐏𝐫𝐨𝐜𝐞𝐬𝐬 𝐂𝐫𝐞𝐚𝐭𝐢𝐨𝐧: msbuild.exe ✅ 𝐌𝐨𝐝𝐮𝐥𝐞 𝐋𝐨𝐚𝐝𝐬: 𝑴𝒊𝒄𝒓𝒐𝒔𝒐𝒇𝒕.𝑽𝒊𝒔𝒖𝒂𝒍𝑺𝒕𝒖𝒅𝒊𝒐.𝑻𝒆𝒙𝒕𝑻𝒆𝒎𝒑𝒍𝒂𝒕𝒊𝒏𝒈*.𝒅𝒍𝒍 DLLs ✅ 𝐅𝐢𝐥𝐞 𝐂𝐫𝐞𝐚𝐭𝐢𝐨𝐧: T4 and output files under 📁 𝑪:\𝑼𝒔𝒆𝒓𝒔\<𝒖𝒔𝒆𝒓>𝑨𝒑𝒑𝑫𝒂𝒕𝒂\𝑳𝒐𝒄𝒂𝒍\𝑻𝒆𝒎𝒑\ ipurple.team/2026/08/24/t...
010
netbiosX @netbiosx.bsky.social · 26/08/2026
The iPurple Navigator has been updated to include the recent techniques: 🟣 Provisioning Packages ➡️ Execution 🟣 Mandatory User Profile ➡️ Persistence 🟣 Text Template ➡️ Execution Articles: ⤵️ 🔗 ipurple.team/2026/08/04/p... 🔗 ipurple.team/2026/08/11/m... 🔗 ipurple.team/2026/08/24/t...
021
netbiosX @netbiosx.bsky.social · 25/08/2026
🚨 It looks like text template files can be executed from msbuild.exe without any arguments.
030
netbiosX @netbiosx.bsky.social · 24/08/2026
A quick video of how to use MSBuild.exe to target a .csproj file that has been tampered with multiple text template files and execute code embedded in .tt files.
011
netbiosX @netbiosx.bsky.social · 24/08/2026
📢 Code Execution via Text Template Files 🎙️ T4 .tt files are intended for code and text generation. Threat actors can create or modify a .tt file to abuse legitimate developer tooling (LOLBins) to execute code in the context of a trusted process. ✒️ ipurple.team/2026/08/24/t...
ipurple.team
Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p…
011
netbiosX @netbiosx.bsky.social · 21/08/2026
Before AI, the path was: Technique ➡️ Blog ➡️ Community Reach ➡️ Career Growth ➡️ 💵💶 Now: Technique ➡️ Paid Course / Service ➡️ Direct Monetization 💵💶 The information still exists, it’s just no longer free. 💸💸
010
netbiosX @netbiosx.bsky.social · 20/08/2026
A security-research Proof-of-Concept (POC) demonstrating hardware-breakpoint (CPU debug register) based function hooking as an alternative to traditional in-memory code patching.
github.com
GitHub - Dovughs/mora-hwbp: Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).
Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC). - Dovughs/mora-hwbp
020
netbiosX @netbiosx.bsky.social · 17/08/2026
🚨 Code Injection via the 𝐌𝐞𝐬𝐬𝐚𝐠𝐞𝐁𝐨𝐱𝐈𝐧𝐝𝐢𝐫𝐞𝐜𝐭𝐖 API. 𝑷𝒓𝒐𝒄𝒆𝒔𝒔 🔴 Shellcode is stored in allocated process memory 🔴 The 𝒍𝒑𝒔𝒛𝑰𝒄𝒐𝒏 field ➡️ points to the shellcode address 🔴 The 𝒍𝒑𝒇𝒏𝑴𝒔𝒈𝑩𝒐𝒙𝑪𝒂𝒍𝒍𝒃𝒂𝒄𝒌 has the same address 🟰 lpszIcon address 🔴 Help event invokes 𝒍𝒑𝒇𝒏𝑴𝒔𝒈𝑩𝒐𝒙𝑪𝒂𝒍𝒍𝒃𝒂𝒄𝒌 ➡️ Shellcode Trigger
010
netbiosX @netbiosx.bsky.social · 11/08/2026
Persistence | Mandatory User Profile - Playbook & Detection Strategies
ipurple.team
Mandatory User Profile
The file NTUSER.MAN is a Windows user-profile registry hive used with mandatory profiles. It contains pre-defined configuration settings that are loaded into the registry (HKEY_CURRENT_USER) when t…
001
netbiosX @netbiosx.bsky.social · 04/08/2026
SquidC5 - Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination)
github.com
GitHub - SquidSec/SquidC5: Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) for authorized red team & pentest. Built by SquidSec.
Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) for authorized red team & pentest. Built by SquidSec. - SquidSec/SquidC5
030
netbiosX @netbiosx.bsky.social · 04/08/2026
Code Execution - Provisioning Packages
ipurple.team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…
021
netbiosX @netbiosx.bsky.social · 20/07/2026
Shellph - a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode
github.com
GitHub - xirtam2669/Shellph: Shellph is a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode. Named after my cat (Belph)
Shellph is a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode. Named after my cat (Belph) - xirtam2669/Shellph
020
netbiosX @netbiosx.bsky.social · 16/07/2026
📝 Earlier this week, I wrote an article about how to abuse AMSI for persistence and detection guidance. You can find the visualization diagram below. 🔗 ipurple.team/2026/07/13/a...
000
netbiosX @netbiosx.bsky.social · 16/07/2026
kirchware.com
Modular PIC Implant Design
For the past many months I have been working on (what I think) is a novel design for PIC shellcode implants.
001
netbiosX @netbiosx.bsky.social · 14/07/2026
slashsec.at
Writing an Evasive .NET Shellcode Loader | slashsec
A technical overview of how to load malicious code into .NET assemblies
021
netbiosX @netbiosx.bsky.social · 14/07/2026
mrtiz.github.io
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
Disclaimer. This research is published for educational and defensive purposes only. I do not endorse the use of this technique for unauthorized access to any computer system. Always obtain explicit wr...
000
netbiosX @netbiosx.bsky.social · 13/07/2026
🎙️ Threat actors with elevated permissions could register a fake AMSI provider to establish persistence. 𝑫𝒆𝒕𝒆𝒄𝒕𝒊𝒐𝒏 𝑺𝒕𝒓𝒂𝒕𝒆𝒈𝒊𝒆𝒔 ✅️ 7 - Sysmon Fake AMSI Provider DLL ✅️ 4663 - Modification of HKLM\SOFTWARE\Microsoft\AMSI\Providers Registry Key ✅️ 4688 - regsvr32 Process ✒️ ipurple.team/2026/07/13/a...
ipurple.team
AMSI Provider
The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However,…
011
netbiosX @netbiosx.bsky.social · 09/07/2026
Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.
github.com
GitHub - Chaelsoo/nimcrypt: Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.
Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender. - Chaelsoo/nimcrypt
010
netbiosX @netbiosx.bsky.social · 08/07/2026
screetsec.com
Maland | Offensive PowerShell for Red Teamer with Defense Evasion Techniques
This post cover how PowerShell becomes a main tool in offensive operations starting with the weaponization, delivery, attak-chain and post-exploitation.
010
netbiosX @netbiosx.bsky.social · 08/07/2026
github.com
GitHub - Zypherion-Technologies/Nemesis: .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.
.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries. - Zypherion-Technologies/Nemesis
010
netbiosX @netbiosx.bsky.social · 07/07/2026
PhantomFS - a Windows honeypot that projects convincing decoy files, credentials, financials, SSH keys, into a virtual directory via ProjFS, then fires instant Event Log and Toast alerts the moment an attacker opens one.
github.com
GitHub - AlloySecureGroup/PhantomFS: PhantomFS is a Windows honeypot that projects convincing decoy files — credentials, financials, SSH keys — into a virtual directory via ProjFS, then fires instant ...
PhantomFS is a Windows honeypot that projects convincing decoy files — credentials, financials, SSH keys — into a virtual directory via ProjFS, then fires instant Event Log and Toast alerts the mom...
000
netbiosX @netbiosx.bsky.social · 07/07/2026
P³-Shellcode Loader - a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms.
github.com
GitHub - Orange-Cyberdefense/p3-loader: P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location...
P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote ...
000
netbiosX @netbiosx.bsky.social · 07/07/2026
Process Parameter Poisoning - an attack technique that is used to inject code on foreign processes, without triggering typical detection mechanisms.
sensepost.com
SensePost | Process Parameter Poisoning
000
netbiosX @netbiosx.bsky.social · 06/07/2026
A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation github.com/xec412/XeraLdr
github.com
GitHub - xec412/XeraLdr: A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation.
A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Sleep Obfuscation. - xec412/XeraLdr
020
netbiosX @netbiosx.bsky.social · 06/07/2026
Windows Service - Playbook & Detection Strategies ipurple.team/2026/07/06/w...
ipurple.team
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
010
netbiosX @netbiosx.bsky.social · 02/07/2026
github.com
GitHub - n0qword/win32k-callback-detouring: Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
Abusing the win32k.sys kernel callback mechanism for arbitrary code execution - n0qword/win32k-callback-detouring
010
netbiosX @netbiosx.bsky.social · 01/07/2026
github.com
GitHub - KingOfTheNOPs/CDP-Enable-BOF: Beacon Object File to Enable Chrome DevTools Protocol (CDP)
Beacon Object File to Enable Chrome DevTools Protocol (CDP) - KingOfTheNOPs/CDP-Enable-BOF
021
netbiosX @netbiosx.bsky.social · 30/06/2026
Hollow - a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.
github.com
GitHub - Chaelsoo/Hollow
Contribute to Chaelsoo/Hollow development by creating an account on GitHub.
010
netbiosX @netbiosx.bsky.social · 30/06/2026
SpotifyC2 - a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery, without requiring the Spotify Web API.
github.com
GitHub - NirvanaOn/SpotifyC2: SpotifyC2 is a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output de...
SpotifyC2 is a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery, without requiring t...
020
netbiosX @netbiosx.bsky.social · 29/06/2026
practicalsecurityanalytics.com
Dumping LSASS Without Touching Disk: Improvements to ShadowDumper
While integrating LSASS dumping techniques into SpecterInsight’s dumper module, I used Offensive-Panda’s ShadowDumper as a reference point. That tool is great collection of LSASS dump techniques, b…
000
netbiosX @netbiosx.bsky.social · 28/06/2026
Abusing GitLab CI Runners as a Command and Control Framework vrls.ws/posts/abusin...
vrls.ws
Abusing GitLab CI Runners as a Command and Control Framework
Explore how GitLab self-hosted runners can be repurposed as a fully functional Command and Control framework using a legitimate, digitally signed binary. Covers the GitRunner C2 proof-of-concept, exec...
010
netbiosX @netbiosx.bsky.social · 27/06/2026
NebulaPulsar - a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project.
github.com
GitHub - iss4cf0ng/NebulaPulsar: NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project.
NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project. - iss4cf0ng/NebulaPulsar
020
netbiosX @netbiosx.bsky.social · 26/06/2026
bl4ckarch.github.io
One Bool. Six Shells. AMSI’s Design Problem.
A research study into the Anti-Malware Scan Interface (AMSI) combining Ghidra decompilation of amsi.dll, Frida dynamic instrumentation, and live bypass testing with Windows Defender active. Six techni...
000
netbiosX @netbiosx.bsky.social · 22/06/2026
iPurple playbooks are now mapped to ATT&CK. The custom navigator has: 1️⃣ New Techniques with new ATT&CK IDs 2️⃣ Techniques and Sub-Techniques mapped to the iPurple playbook So if you are looking for a purple team playbook or detection guidance, visit the Navigator 🔗 navigator.ipurple.team
navigator.ipurple.team
iPurple.team · ATT&CK Navigator
iPurple.team purple-team coverage matrix built on MITRE ATT&CK (Windows Enterprise).
020
netbiosX @netbiosx.bsky.social · 17/06/2026
📢 QoS Policies - Restrict EDR agents Traffic from generating telemetry & Detection Strategies 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐒𝐭𝐫𝐚𝐭𝐞𝐠𝐲 - 𝐄𝐯𝐞𝐧𝐭 𝐈𝐃𝐬 ✅️️️ 5857 - CIM Provider ✅️️️ 4104 - PowerShell ScriptBlock ✅️️️ 4663 - Registry Key Modification ✅️️️ 4688 - Process Creation ✅️️️ qoswmi.dll 🖊️ ipurple.team/2026/06/17/q...
ipurple.team
QoS Policies
In Windows, a Quality of Service (QoS) policy is a rule that handles outbound network traffic. Specifically, it is used to cap the outbound bandwidth of a process, port, or protocol. Organizations …
021
netbiosX @netbiosx.bsky.social · 09/06/2026
ipurple.team
WinGet
WinGet also known as Windows Package Manager, is Microsoft’s command-line for discovering, installing, upgrading, configuring, and removing applications on Windows. It is commonly used by Adm…
021
netbiosX @netbiosx.bsky.social · 15/05/2026
Detection of EntryPoint Hijacking consists of the following: 1️⃣ EntryPoint address escapes the module’s DllBase range 2️⃣ MEM_IMAGE → MEM_PRIVATE transition 3️⃣ OriginalBase fails validation ✒️ Read More: ipurple.team/2026/05/13/e...
000
netbiosX @netbiosx.bsky.social · 13/05/2026
🎙️ EntryPoint Hijacking introduces a stealthier approach to code injection. 🛠️ 𝐀 𝐍𝐞𝐰 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧‑𝐂𝐚𝐩𝐚𝐛𝐢𝐥𝐢𝐭𝐲 is introduced that monitors: 🧠 The memory address of the EntryPoint 🧬 Changes to the EntryPoint memory type 🛑 OriginalBase validity ✒️ 𝐑𝐞𝐚𝐝 𝐭𝐡𝐞 𝐟𝐮𝐥𝐥 𝐚𝐫𝐭𝐢𝐜𝐥𝐞 ipurple.team/2026/05/13/e...
ipurple.team
EntryPoint Hijacking
The technique of EntryPoint Hijacking introduces a stealthier approach to code injection as it doesn’t use API calls that create a new thread within the context of a process, and it independe…
000
netbiosX @netbiosx.bsky.social · 07/05/2026
🚨 Cross‑Session Activation is a detection gap hiding in plain sight. 💡 The technique abstract below highlights the minimum viable signals for defenders. 💭 Interesting to know if this technique is part of your threat emulation library. #detectionengineering #purpleteam #blueteam
010
netbiosX @netbiosx.bsky.social · 07/05/2026
github.com
GitHub - depthsecurity/PositiveIntent: Evasive loader for .NET Framework assemblies
Evasive loader for .NET Framework assemblies. Contribute to depthsecurity/PositiveIntent development by creating an account on GitHub.
011
netbiosX @netbiosx.bsky.social · 06/05/2026
📉 𝐂𝐲𝐛𝐞𝐫 𝐬𝐢𝐠𝐧𝐚𝐥 𝐢𝐬 𝐝𝐫𝐨𝐩𝐩𝐢𝐧𝐠. 📈 𝐀𝐈 𝐧𝐨𝐢𝐬𝐞 𝐢𝐬 𝐫𝐢𝐬𝐢𝐧𝐠. To help, I created a list of active cybersecurity blogs written by people who still publish real research. If you follow any of these already (or have gems I should add), let me know. github.com/netbiosX/Cyb...
github.com
GitHub - netbiosX/CyberSec-Blogs: Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. Most are personal blogs maint...
Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. Most are personal blogs maintained by practitioners who publ...
020