Sign in

Raphael Mudge

@raphaelmudge.bsky.social
404 followers 39 following 116 posts

Riding around in the breeze. USAF Veteran.

PostsRepliesMedia
Raphael Mudge @raphaelmudge.bsky.social · 25/09/2026
Was linked to this project: Piclang, a statically typed programming language that compiles to Linux and Windows shellcode. I'm a big fan of language-tooling to give flexibility or expose abstractions that are too hard doing things the normal way. Neat to see this work github.com/zarkones/Pic...
130
Raphael Mudge @raphaelmudge.bsky.social · 23/09/2026
Entropia - a compiled language that outputs PIC and Beacon Object Files. Includes AOP-style mix-in modules to hook functions, execute code at begin/end of program. Implements several runtime tradecrafts as examples. Author xaff.dev docs.entropykit.com github.com/entropykit/e...
021
Raphael Mudge @raphaelmudge.bsky.social · 22/09/2026
If you are in London, @rastamouse.me is THE headliner speaker at the beac0n red teaming conference tomorrow talking CS and CPL tradecraft. Tickets here: www.eventbrite.co.uk/e/beacon-26-... Org/conf details here: beac0n.org
251
Raphael Mudge @raphaelmudge.bsky.social · 21/09/2026
It's a Mod, Mod, Mod, Mod World aff-wg.org/2026/09/21/i... TCG update: - .spec files are now modules w/ query-able meta-info - Added hexdump and dump to see intermediate outputs - Added encode&mask for content transforms And, a modular demo for encode/mask: tradecraftgarden.org/simpletransf...
aff-wg.org
It’s a Mod, Mod, Mod, Mod World
n options.
053
Reposted by Raphael Mudge
Phrack Zine @phrack.org · 18/09/2026
Your weekend reading is here! A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by Mikko archives.phrack.org/dl/73/the-pr...
Art from Phrack 73, alien planet scene
0134
Reposted by Raphael Mudge
BallisKit @balliskit.bsky.social · 18/09/2026
Introducing Mirage C2 🥷 — our new modular, in-memory macOS implant for DarwinOps. Shell, SOCKS proxy, secret extraction + private techniques for process injection, privilege escalation, TCC bypass & persistence. The full macOS attack chain, from initial access to post-exploitation. #redteam
012
Reposted by Raphael Mudge
5pider @5pider.net · 17/09/2026
New Release Havoc Professional 0.8: Leviathan 🩸 - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored port forwarding and sleep masking - Enhanced .NET/PowerSafe execution - In-Memory PE Execution and BOF-PE support Release: www.infinitycurve.org/blog/leviathan
infinitycurve.org
Havoc Professional 0.8: Leviathan
Introducing Kaine User-Defined C2, expanded Linux post-ex capabilities, refactored port forwarding and sleep masking, enhanced .NET/PowerSafe execution, Beacon Object File improvements, In-Memory PE E...
084
Reposted by Raphael Mudge
Cobalt Strike @cobaltstrike.bsky.social · 11/09/2026
We're looking forward to Beacon 2026, where RastaMouse will present "Yet Another Crystal Palace Talk: Evasion Tradecraft in the Cobalt Strike Ecosystem". Join us for a day of technical content focused on real-world tradecraft. ow.ly/MHUr50ZMG4o 📍 St Ethelburga's, London, UK 📅 September 23
042
Raphael Mudge @raphaelmudge.bsky.social · 07/09/2026
Playing a Different Game: Rethinking Modern Defense Evasion c0rnbread.com/playing-a-di... """Sometimes the most effective tradecraft isn't the most technically sophisticated. You don't always win by playing the game better and better, but by playing beyond the rules of the game.""" Mmmm hmmm...
065
Raphael Mudge @raphaelmudge.bsky.social · 25/08/2026
Armitage and Metasploit Collaboration (NoVa Hackers - May 2011) I thought this one was lost. One of my earliest talks on the red team collaboration vision for Armitage and some reflection from using it in some 2011 exercises. www.youtube.com/watch?v=Mjr9...
youtube.com
Armitage and Metasploit Collaboration Raphael Mudge NoVa Hackers May 2011
YouTube video by Georgia Weidman
3113
Reposted by Raphael Mudge
Chris Truncer @christruncer.bsky.social · 25/08/2026
I always look forward to when we, CISA’s red team, gets to publish our reports, and today is one of those days! “A Tale of Two SOCs” - a story where we targeted two different orgs, with the same tradecraft, and very different responses. Read it! - www.cisa.gov/news-events/...
cisa.gov
A Tale of Two SOCs: Insights From Two Red Team Assessments | CISA
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key actions to protect your organization from…
042
Raphael Mudge @raphaelmudge.bsky.social · 19/08/2026
The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike by Will Burgess [Beware, marketing wall will ask for email few mins in] www.cobaltstrike.com/the-black-ha... Demos a Universal Loader which modularizes loader problem set & allows mix/match of tradecraft in it. 🙌
0132
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 19/08/2026
@raphaelmudge.bsky.social github.com/sliverarmory...
github.com
GitHub - sliverarmory/crystal-grotto: Golang Port of Crystal Palace
Golang Port of Crystal Palace. Contribute to sliverarmory/crystal-grotto development by creating an account on GitHub.
153
Reposted by Raphael Mudge
Include Security @includesecurity.bsky.social · 10/08/2026
Hi everyone, our latest post explores the practical considerations of AI-assisted source code analysis, evaluating the pros and cons of frontier and locally-hosted models while using a variety of harness orchestration designs. blog.includesecurity.com/2026/08/web-...
blog.includesecurity.com
Web App Pentesting in the AI Era - Include Security Research Blog
The IncludeSec team explores the practical considerations of AI-assisted source code analysis. Observing results produced with frontier vs locally-hosted models, various harness orchestration designs,...
022
Reposted by Raphael Mudge
Metasploit @metasploit-r7.bsky.social · 30/07/2026
Metasploit 6.5 is out just in time for Hack Summer Camp. This release comes with Malleable C2 support for Meterpreter, more relaying improvements and an integrated MCP server. Check out all the details here: www.rapid7.com/blog/post/pt-metaspl…
rapid7.com
Rapid7
Metasploit Framework 6.5 launches with Malleable C2 profile support, new MCP server integration support for AI-tooling, NTLM relaying upgrades, and MITRE ATT&CK tagging to streamline threat emulation
092
Raphael Mudge @raphaelmudge.bsky.social · 28/07/2026
Carrying NCCDC Forward alexlevinson.wordpress.com/2026/07/28/c... A new home for NCCDC ncr.foundation/news/nccdc-n... The National Collegiate Cyber Defense Competition is moving to NCRF, a non-profit helmed by long-time event volunteers Alex Levinson & Dave Cowen. I trust both w/ this stewardship
alexlevinson.wordpress.com
Carrying NCCDC Forward
After 21 years of stewardship, UTSA and the Center for Infrastructure Assurance and Security are transitioning the National Collegiate Cyber Defense Competition to a new home. Dave Cowen and I are …
042
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 28/07/2026
I wrote a little bit about COFF Mixing rastamouse.me/coff-mixing/
284
Reposted by Raphael Mudge
Cobalt Strike @cobaltstrike.bsky.social · 21/07/2026
Join Cobalt Strike’s Will Burgess at the Fortra Black Hat USA booth #2939 for his presentation “The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike.” See you there Weds, August 5th at 12:30 p.m. Full schedule here www.cobaltstrike.com/the-black-hat-…
021
Reposted by Raphael Mudge
FallenAngel666 @fallenangelc2.bsky.social · 25/07/2026
Hi, bluesky. I just created my account. And I wanted to share two of my most recent posts here about Crystal Palace and Mythic. fallenangel666-blog.pages.dev/posts/crysta... fallenangel666-blog.pages.dev/posts/mythic...
fallenangel666-blog.pages.dev
crystal-palace. tradecraft link PIC y evasion de EDRs | Fuck the critics
Esto no es un tutorial. Ya existen muchos. Esto es una inmersión arquitectónica profunda en Crystal Palace, el linker PIC y el lenguaje de script de enlazado cr
162
Reposted by Raphael Mudge
Max @sttlr.bsky.social · 24/07/2026
My first blog post is up: "Pop a Calc: The Crystal Palace Way" Reinventing msfvenom's Pop a Calc shellcode using Crystal Palace and exploring offensive tradecraft vs capability separation. kerekesha.com/blog/pop-a-c...
kerekesha.com
Max Kerekesha
Flaneur. Hacker.
074
Reposted by Raphael Mudge
Calzone @calz0n3.bsky.social · 23/07/2026
Got a little bof2pico tool working (based on @raphaelmudge.bsky.social's "Simple BOF Runner") to convert BOFs into PICOs that celebi knows how to execute :) parsing arbitrary argument datatypes into the BOF argument format is a little more challenging, though.
Screenshot demonstrating the TrustedSec sc_stop BOF running as a PICO!
152
Raphael Mudge @raphaelmudge.bsky.social · 20/07/2026
"Some Magic Linker" - a tour of Crystal Palace and TCG. This video demos CPL's features and how they support time-of-use-composition. This enables modular tradecraft & capability recombination. This encourages use/color-agnostic tradecraft, separable from specific capability vimeo.com/1209887681
vimeo.com
Some Magic Linker
A feature tour of Crystal Palace.
094
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 17/07/2026
Had a little play with user-defined intrinsics in Crystal Palace to POC a new intrinsic that I'd like to see get official adoption 🙏🏻 rastamouse.me/crystal-pala...
131
Raphael Mudge @raphaelmudge.bsky.social · 16/07/2026
LSH delish aff-wg.org/2026/07/16/l... Another CPL and TCG update: Specify language-specific exception handlers in +unwind, user-defined intrinsics, and callnear to make before/after more useful.
aff-wg.org
LSH delish
Another Crystal Palace and Tradecraft Garden release is now available. This release fills some gaps from recent releases and rounds out the feature set (aka, stuff I wanted to ship, but didn’…
155
Reposted by Raphael Mudge
Bingus @sizeable-bingus.bsky.social · 14/07/2026
New post about a CET compatible stack spoofing technique and a loader integrating it :) bigbingus.com/posts/bingus... github.com/Sizeable-Bin...
bigbingus.com
BingusLdr: CET Compatible Stack Spoofing | bigbingus.com
BingusLdr: CET Compatible Stack Spoofing
175
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 06/07/2026
[BLOG] A quick look at Crystal Palace's hook chains and why you should consider them over single hooks for layering evasive tradecraft. rastamouse.me/cpl-hook-cha...
052
Reposted by Raphael Mudge
pard0p.bsky.social @pard0p.bsky.social · 30/06/2026
Here’s a technical overview of ADWS, why it matters, and how it can be leveraged for stealthier Active Directory enumeration. josupalacios99.github.io/blog/en/post...
josupalacios99.github.io
ADWS: enumerating Active Directory through the back door
Almost all Active Directory enumeration goes through LDAP (389/636), which is precisely the most watched channel in the domain. ADWS is a side door on port 9389 that accepts the same LDAP queries but ...
022
Raphael Mudge @raphaelmudge.bsky.social · 29/06/2026
Cruising Forward with the Tradecraft Garden New update: * New cpl [verb] CLI interface * We have an install script! * More API hashing options aff-wg.org/2026/06/29/c...
aff-wg.org
Cruising Forward with the Tradecraft Garden
A new Tradecraft Garden and Crystal Palace release is available. This release introduces a proper install script and consolidates its commands behind a cpl [verb] CLI interface. I’ve also added an …
063
Reposted by Raphael Mudge
Dirk-jan @dirkjanm.io · 22/06/2026
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy! dirkjanm.io/bypassing-co...
dirkjanm.io
Bypassing Conditional Access policies that have a resource exclusion
There is a documented enforcement gap in Conditional Access policies that apply to “all resources” but have an exclusion for at least one resource. What is not documented, is that this gap is much lar...
063
Raphael Mudge @raphaelmudge.bsky.social · 10/06/2026
A Long-running BOF Component Contract aff-wg.org/2026/06/10/a... An architecture and Crystal Palace best practice focused riff on Async PICOs and Custom Beacon Wakeups in Cobalt Strike by Marcos Gonzalez Hermida www.nccgroup.com/research/asy... Short LR-BOFs demo: vimeo.com/1200217753
vimeo.com
Long-running BOFs Demo
An architectural POC for long-running BOFs.
021
Reposted by Raphael Mudge
Cobalt Strike @cobaltstrike.bsky.social · 10/06/2026
Cobalt Strike 4.13 is live! Say "Hello World" to our Beacon Interpreter for native C scripting - plus an LLVM Beacon, smoother docking UX, sharper payload management and more. Read about all the new features in the release blog! ow.ly/bynP50Zaae4
014
Raphael Mudge @raphaelmudge.bsky.social · 10/06/2026
I always loved software release days. Whenever I worked an update, I was imagining the things folks could do after. But, I also made changes inspired by a question or need from individuals too. I never promised anything. I liked to let the action of shipped code, addressing X, etc. be the message.
020
Reposted by Raphael Mudge
5pider @5pider.net · 05/06/2026
New Release: Havoc Professional 0.7 K-Noir 🐺 New Linux implant for x86_64 and AArch64, Stack Spoofing related improvments such as CET compliance and a function rule system, new registry manipulation extension and injection based capabilities. Link: www.infinitycurve.org/blog/k-noir
infinitycurve.org
Havoc Professional 0.7: K-Noir
An introduction to Havoc Professional 0.7 K-Noir, featuring a new Linux implant for x86_64 and AArch64, CET compliant stack spoofing and rules systems, new Direct and P2P communication channels, new m...
052
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 05/06/2026
Cobalt Strike 4.13 has a new Aggressor hook to support BOF cocktails. Here's a quick walkthrough: rastamouse.me/bof-cocktail...
023
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 05/06/2026
Interesting post by Marcos Gonzalez Hermida: Async PICOs and Custom Beacon Wakeups in Cobalt Strike. www.nccgroup.com/research/asy...
021
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 04/06/2026
I had the occasion to play with EAF the other day, so I added a bypass to the TCG's PIC services module. It provides a way to resolve Win32 APIs through gadget in NTDLL's .text section.
072
Reposted by Raphael Mudge
Chris Truncer @christruncer.bsky.social · 04/06/2026
There are other offensive services CISA does and there are other openings. But this one specifically is for red team, and we are every sense of that, an actual red team. We don’t do pen tests, mobile app reviews, etc. It’s one of the coolest missions you could join.
011
Raphael Mudge @raphaelmudge.bsky.social · 03/06/2026
Crystal Kit - Sliver - A sliver port of @rastamouse.me 's Crystal Kit by Simone Licitra: github.com/licitrasimon... Via: www.linkedin.com/posts/simone... (Cool to see Crystal Kit for CS, Xenon for Mythic, and now Sliver. Really really cool)
github.com
GitHub - licitrasimone/CrystalSliver: Crystal Palace Evasion kit for Sliver
Crystal Palace Evasion kit for Sliver. Contribute to licitrasimone/CrystalSliver development by creating an account on GitHub.
071
Raphael Mudge @raphaelmudge.bsky.social · 01/06/2026
Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)
aff-wg.org
Relax and unwind in the Tradecraft Garden
We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…
2148
Raphael Mudge @raphaelmudge.bsky.social · 01/06/2026
I'm a little late on this. Primo (x.com/cr4ckeddd) is continuing work on TinyC2. Added built-in Lua scripting to it: x.com/cr4ckeddd/st... Project is at: github.com/0xPrimo/Tiny... Seems a bunch of other post-ex added too.
010
Reposted by Raphael Mudge
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 28/05/2026
Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual Also manages to sprinkle in a few references to not using CVD as being not "responsible". (Microsoft was a big proponent of the term "responsible disclosure", which has gone by the […]
infosec.exchange
Original post on infosec.exchange
011
Raphael Mudge @raphaelmudge.bsky.social · 28/05/2026
Analysis of a Ransomware Breach was inspired partially by outcry over disclosure of the Bad Successor vuln. aff-wg.org/2025/09/26/a... "Uncoordinated disclosures that put [POC] code for unpatched vulnerabilities into the hands of bad actors are never justifiable" www.microsoft.com/en-us/msrc/b...
021
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 26/05/2026
Silly little post experimenting with module stomping PIC. rastamouse.me/module-stomp...
133
Reposted by Raphael Mudge
WulStack.bsky.social @d1to.bsky.social · 25/05/2026
As part of my thesis, I developed a Proof of Concept for a UDRL using Gargoyle and inspired by Crystal Palace, developed by @raphaelmudge.bsky.social . github.com/WulStack/gar... I will design a complete UDRL based on this first project in the next month.
022
Raphael Mudge @raphaelmudge.bsky.social · 24/05/2026
Just came across this Sleep-hooking UDRL demonstration of Gargoyle using Crystal Palace by WulStack: github.com/WulStack/gar... The above led me to "Gargoyle, a decade later" posted by Josh Lospinoso -- Very philosophical. Worth a read. lospino.so/blog/gargoyl...
lospino.so
Gargoyle, a decade later | Josh Lospinoso
A reflective retrospective on Gargoyle, temporal memory state, the 2026 refresh, and what better validation teaches defenders.
064
Raphael Mudge @raphaelmudge.bsky.social · 21/05/2026
Modules and Monoliths aff-wg.org/2026/05/21/m...
aff-wg.org
Modules and Monoliths
Last week, memN0ps published DoublePulsar: A User-defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era. It’s a lengthy blog post, about 50 printed pages. And, most of those are…
032
Raphael Mudge @raphaelmudge.bsky.social · 16/05/2026
I met Fagan at SECCDC this year. He just passed the CRTL: Congrats on passing CRTL Fagan. It was great to meet you in person too. It's really cool seeing you and the next generation of researchers tackling today's deep work right out the gate. www.linkedin.com/posts/fagan-...
linkedin.com
I just passed Certified Red Team Lead (CRTL) with full points! CRTL is an advanced malware development and EDR evasion certification, one of the more technical certs in the red team space. I got… |...
I just passed Certified Red Team Lead (CRTL) with full points! CRTL is an advanced malware development and EDR evasion certification, one of the more technical certs in the red team space. I got ac...
020
Reposted by Raphael Mudge
RastaMouse @rastamouse.me · 09/05/2026
I have a new version of the CrystalC2 client that supports BOF cocktails. It's also using the CPL linker sidecar API.
151