Sign in

RastaMouse

@rastamouse.me
853 followers 65 following 226 posts

make pic +relax

PostsRepliesMedia
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 21/09/2026
It's a Mod, Mod, Mod, Mod World aff-wg.org/2026/09/21/i... TCG update: - .spec files are now modules w/ query-able meta-info - Added hexdump and dump to see intermediate outputs - Added encode&mask for content transforms And, a modular demo for encode/mask: tradecraftgarden.org/simpletransf...
aff-wg.org
It’s a Mod, Mod, Mod, Mod World
n options.
053
Reposted by RastaMouse
Cobalt Strike @cobaltstrike.bsky.social · 17/09/2026
We've been heads down building, but we couldn't wait to show off what we're working on. Join the Cobalt Strike team for a live demo on October 6 that includes a look at Aggressor AI, the next release, CSRL additions, and training updates. Register now: ow.ly/favW50ZOP0w
001
Reposted by RastaMouse
5pider @5pider.net · 17/09/2026
New Release Havoc Professional 0.8: Leviathan 🩸 - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored port forwarding and sleep masking - Enhanced .NET/PowerSafe execution - In-Memory PE Execution and BOF-PE support Release: www.infinitycurve.org/blog/leviathan
infinitycurve.org
Havoc Professional 0.8: Leviathan
Introducing Kaine User-Defined C2, expanded Linux post-ex capabilities, refactored port forwarding and sleep masking, enhanced .NET/PowerSafe execution, Beacon Object File improvements, In-Memory PE E...
084
Reposted by RastaMouse
Dirk-jan @dirkjanm.io · 14/09/2026
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/ask...
github.com
GitHub - dirkjanm/askWAM: Ask the Web Account Manager (WAM) for Entra ID tokens
Ask the Web Account Manager (WAM) for Entra ID tokens - dirkjanm/askWAM
1103
RastaMouse @rastamouse.me · 11/09/2026
Hopefully the talk is better than my mug shot… no promises though.
233
Reposted by RastaMouse
outflank.bsky.social @outflank.bsky.social · 08/09/2026
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: ow.ly/QZ4x50ZKOmm
064
RastaMouse @rastamouse.me · 07/09/2026
This is a moment of enlightenment I hope everyone can experience at least once. All bets are off once you realise you're playing a rigged game.
031
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 07/09/2026
Playing a Different Game: Rethinking Modern Defense Evasion c0rnbread.com/playing-a-di... """Sometimes the most effective tradecraft isn't the most technically sophisticated. You don't always win by playing the game better and better, but by playing beyond the rules of the game.""" Mmmm hmmm...
065
Reposted by RastaMouse
Chris Truncer @christruncer.bsky.social · 25/08/2026
I always look forward to when we, CISA’s red team, gets to publish our reports, and today is one of those days! “A Tale of Two SOCs” - a story where we targeted two different orgs, with the same tradecraft, and very different responses. Read it! - www.cisa.gov/news-events/...
cisa.gov
A Tale of Two SOCs: Insights From Two Red Team Assessments | CISA
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key actions to protect your organization from…
042
Reposted by RastaMouse
Dirk-jan @dirkjanm.io · 20/08/2026
📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4-day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg: events.outsidersecurity.nl/entra-26-11/
events.outsidersecurity.nl
Training: Offensive Entra ID (Azure AD) and Hybrid AD security
Nov. 16 – 19, 2026
021
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 19/08/2026
The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike by Will Burgess [Beware, marketing wall will ask for email few mins in] www.cobaltstrike.com/the-black-ha... Demos a Universal Loader which modularizes loader problem set & allows mix/match of tradecraft in it. 🙌
0132
RastaMouse @rastamouse.me · 19/08/2026
@raphaelmudge.bsky.social github.com/sliverarmory...
github.com
GitHub - sliverarmory/crystal-grotto: Golang Port of Crystal Palace
Golang Port of Crystal Palace. Contribute to sliverarmory/crystal-grotto development by creating an account on GitHub.
153
RastaMouse @rastamouse.me · 18/08/2026
Me waiting for the next Crystal Palace update.
static.klipy.com
Man Waiting Patiently
ALT: Man Waiting Patiently
130
RastaMouse @rastamouse.me · 13/08/2026
Seal 🦭
010
RastaMouse @rastamouse.me · 12/08/2026
Spacey wacey
010
RastaMouse @rastamouse.me · 10/08/2026
Lovely jubbly
010
RastaMouse @rastamouse.me · 08/08/2026
Baggers
010
RastaMouse @rastamouse.me · 06/08/2026
Rasta got chickens
4533
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 28/07/2026
Carrying NCCDC Forward alexlevinson.wordpress.com/2026/07/28/c... A new home for NCCDC ncr.foundation/news/nccdc-n... The National Collegiate Cyber Defense Competition is moving to NCRF, a non-profit helmed by long-time event volunteers Alex Levinson & Dave Cowen. I trust both w/ this stewardship
alexlevinson.wordpress.com
Carrying NCCDC Forward
After 21 years of stewardship, UTSA and the Center for Infrastructure Assurance and Security are transitioning the National Collegiate Cyber Defense Competition to a new home. Dave Cowen and I are …
042
RastaMouse @rastamouse.me · 28/07/2026
I wrote a little bit about COFF Mixing rastamouse.me/coff-mixing/
284
RastaMouse @rastamouse.me · 27/07/2026
COFF mixing is kewl
020
Reposted by RastaMouse
Calzone @calz0n3.bsky.social · 26/07/2026
bof2pico: Simple helper utility for converting BOFs into PICOs (with hardcoded arguments) that celebi knows how to understand. github.com/ofasgard/cel... Thanks to @rastamouse.me for the suggestion to include a format specifier with the arguments!
062
Reposted by RastaMouse
FallenAngel666 @fallenangelc2.bsky.social · 25/07/2026
Hi, bluesky. I just created my account. And I wanted to share two of my most recent posts here about Crystal Palace and Mythic. fallenangel666-blog.pages.dev/posts/crysta... fallenangel666-blog.pages.dev/posts/mythic...
fallenangel666-blog.pages.dev
crystal-palace. tradecraft link PIC y evasion de EDRs | Fuck the critics
Esto no es un tutorial. Ya existen muchos. Esto es una inmersión arquitectónica profunda en Crystal Palace, el linker PIC y el lenguaje de script de enlazado cr
162
RastaMouse @rastamouse.me · 24/07/2026
@raphaelmudge.bsky.social maybe of interest kerekesha.com/blog/pop-a-c...
kerekesha.com
Max Kerekesha
Flaneur. Hacker.
080
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 20/07/2026
"Some Magic Linker" - a tour of Crystal Palace and TCG. This video demos CPL's features and how they support time-of-use-composition. This enables modular tradecraft & capability recombination. This encourages use/color-agnostic tradecraft, separable from specific capability vimeo.com/1209887681
vimeo.com
Some Magic Linker
A feature tour of Crystal Palace.
094
RastaMouse @rastamouse.me · 17/07/2026
Had a little play with user-defined intrinsics in Crystal Palace to POC a new intrinsic that I'd like to see get official adoption 🙏🏻 rastamouse.me/crystal-pala...
131
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 16/07/2026
LSH delish aff-wg.org/2026/07/16/l... Another CPL and TCG update: Specify language-specific exception handlers in +unwind, user-defined intrinsics, and callnear to make before/after more useful.
aff-wg.org
LSH delish
Another Crystal Palace and Tradecraft Garden release is now available. This release fills some gaps from recent releases and rounds out the feature set (aka, stuff I wanted to ship, but didn’…
155
Reposted by RastaMouse
Bingus @sizeable-bingus.bsky.social · 14/07/2026
New post about a CET compatible stack spoofing technique and a loader integrating it :) bigbingus.com/posts/bingus... github.com/Sizeable-Bin...
bigbingus.com
BingusLdr: CET Compatible Stack Spoofing | bigbingus.com
BingusLdr: CET Compatible Stack Spoofing
175
Reposted by RastaMouse
Cobalt Strike @cobaltstrike.bsky.social · 07/07/2026
Building red team curriculum from scratch is expensive. Get student-ready courses that use real red team tools with labs, assessments, and cert pathways included. Less overhead. More impact. #HigherEd #CyberPrograms #CobaltStrike
021
RastaMouse @rastamouse.me · 06/07/2026
[BLOG] A quick look at Crystal Palace's hook chains and why you should consider them over single hooks for layering evasive tradecraft. rastamouse.me/cpl-hook-cha...
052
RastaMouse @rastamouse.me · 29/06/2026
There's no constexpr in C, so the new __ror13_x intrinsic makes it easier to use hashes without the need for strings or pre-computed hashes. Useful when performing tasks like resolving syscalls. Just declare as a DWORD and use.
021
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 29/06/2026
Cruising Forward with the Tradecraft Garden New update: * New cpl [verb] CLI interface * We have an install script! * More API hashing options aff-wg.org/2026/06/29/c...
aff-wg.org
Cruising Forward with the Tradecraft Garden
A new Tradecraft Garden and Crystal Palace release is available. This release introduces a proper install script and consolidates its commands behind a cpl [verb] CLI interface. I’ve also added an …
063
Reposted by RastaMouse
Cobalt Strike @cobaltstrike.bsky.social · 29/06/2026
The gap between “academic cyber labs” and real-world red teaming is shrinking. Students can now train with licensed Cobalt Strike and Zero Point Security’s Red Team Ops, built around real adversary emulation, not abstractions. This is how you teach modern offensive security.
141
Reposted by RastaMouse
Dirk-jan @dirkjanm.io · 22/06/2026
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy! dirkjanm.io/bypassing-co...
dirkjanm.io
Bypassing Conditional Access policies that have a resource exclusion
There is a documented enforcement gap in Conditional Access policies that apply to “all resources” but have an exclusion for at least one resource. What is not documented, is that this gap is much lar...
063
RastaMouse @rastamouse.me · 18/06/2026
I’m a selfie kinda guy now
130
RastaMouse @rastamouse.me · 16/06/2026
MSF's Railgun was massively underrated but incredibly powerful. Resolve and call an API without needing to alloc and run a whole BOF or DLL. I hope to get this implemented nicely in CrystalC2 at some point.
020
RastaMouse @rastamouse.me · 10/06/2026
Props to the team for getting this out now that they have to put up with me distracting them with stupid stories about ppl trying to sell me fish and what flavour Pringles I found.
030
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 10/06/2026
A Long-running BOF Component Contract aff-wg.org/2026/06/10/a... An architecture and Crystal Palace best practice focused riff on Async PICOs and Custom Beacon Wakeups in Cobalt Strike by Marcos Gonzalez Hermida www.nccgroup.com/research/asy... Short LR-BOFs demo: vimeo.com/1200217753
vimeo.com
Long-running BOFs Demo
An architectural POC for long-running BOFs.
021
Reposted by RastaMouse
Cobalt Strike @cobaltstrike.bsky.social · 10/06/2026
Cobalt Strike 4.13 is live! Say "Hello World" to our Beacon Interpreter for native C scripting - plus an LLVM Beacon, smoother docking UX, sharper payload management and more. Read about all the new features in the release blog! ow.ly/bynP50Zaae4
014
Reposted by RastaMouse
XPN @xpnsec.com · 10/06/2026
New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the @specterops.io GhostWorks initiative. Can't wait to show what we've been working on! specterops.io/blog/2026/06...
specterops.io
Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA
Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.
041
RastaMouse @rastamouse.me · 09/06/2026
CS 4.13 is right around the corner, so I've been having a play with the new Beacon Interpreter. This script will stomp a PICO over a module, with unwind data, for post-ex.
020
RastaMouse @rastamouse.me · 06/06/2026
Pushed 0.0.3 of my Crystal Palace VSC extension. It adds new +options, like +relax and +unwind; and adds better syntax support for the ised command.
050
RastaMouse @rastamouse.me · 06/06/2026
More fun with Crystal Palace unwind data.
041
Reposted by RastaMouse
5pider @5pider.net · 05/06/2026
New Release: Havoc Professional 0.7 K-Noir 🐺 New Linux implant for x86_64 and AArch64, Stack Spoofing related improvments such as CET compliance and a function rule system, new registry manipulation extension and injection based capabilities. Link: www.infinitycurve.org/blog/k-noir
infinitycurve.org
Havoc Professional 0.7: K-Noir
An introduction to Havoc Professional 0.7 K-Noir, featuring a new Linux implant for x86_64 and AArch64, CET compliant stack spoofing and rules systems, new Direct and P2P communication channels, new m...
052
RastaMouse @rastamouse.me · 05/06/2026
Cobalt Strike 4.13 has a new Aggressor hook to support BOF cocktails. Here's a quick walkthrough: rastamouse.me/bof-cocktail...
023
RastaMouse @rastamouse.me · 05/06/2026
Interesting post by Marcos Gonzalez Hermida: Async PICOs and Custom Beacon Wakeups in Cobalt Strike. www.nccgroup.com/research/asy...
021
RastaMouse @rastamouse.me · 04/06/2026
I had the occasion to play with EAF the other day, so I added a bypass to the TCG's PIC services module. It provides a way to resolve Win32 APIs through gadget in NTDLL's .text section.
072
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 03/06/2026
Crystal Kit - Sliver - A sliver port of @rastamouse.me 's Crystal Kit by Simone Licitra: github.com/licitrasimon... Via: www.linkedin.com/posts/simone... (Cool to see Crystal Kit for CS, Xenon for Mythic, and now Sliver. Really really cool)
github.com
GitHub - licitrasimone/CrystalSliver: Crystal Palace Evasion kit for Sliver
Crystal Palace Evasion kit for Sliver. Contribute to licitrasimone/CrystalSliver development by creating an account on GitHub.
071
RastaMouse @rastamouse.me · 02/06/2026
Very cool!
010
Reposted by RastaMouse
Raphael Mudge @raphaelmudge.bsky.social · 01/06/2026
Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)
aff-wg.org
Relax and unwind in the Tradecraft Garden
We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…
2148