Sign in

RastaMouse

@rastamouse.me
854 followers 65 following 226 posts

make pic +relax

PostsRepliesMedia
RastaMouse @rastamouse.me · 13/08/2026
Seal 🦭
010
RastaMouse @rastamouse.me · 12/08/2026
Spacey wacey
010
RastaMouse @rastamouse.me · 10/08/2026
Lovely jubbly
010
RastaMouse @rastamouse.me · 08/08/2026
Baggers
010
RastaMouse @rastamouse.me · 06/08/2026
Rasta got chickens
4533
RastaMouse @rastamouse.me · 27/07/2026
COFF mixing is kewl
020
RastaMouse @rastamouse.me · 29/06/2026
There's no constexpr in C, so the new __ror13_x intrinsic makes it easier to use hashes without the need for strings or pre-computed hashes. Useful when performing tasks like resolving syscalls. Just declare as a DWORD and use.
021
RastaMouse @rastamouse.me · 18/06/2026
I’m a selfie kinda guy now
130
RastaMouse @rastamouse.me · 16/06/2026
MSF's Railgun was massively underrated but incredibly powerful. Resolve and call an API without needing to alloc and run a whole BOF or DLL. I hope to get this implemented nicely in CrystalC2 at some point.
020
RastaMouse @rastamouse.me · 09/06/2026
CS 4.13 is right around the corner, so I've been having a play with the new Beacon Interpreter. This script will stomp a PICO over a module, with unwind data, for post-ex.
020
RastaMouse @rastamouse.me · 06/06/2026
Pushed 0.0.3 of my Crystal Palace VSC extension. It adds new +options, like +relax and +unwind; and adds better syntax support for the ised command.
050
RastaMouse @rastamouse.me · 06/06/2026
More fun with Crystal Palace unwind data.
041
RastaMouse @rastamouse.me · 04/06/2026
I had the occasion to play with EAF the other day, so I added a bypass to the TCG's PIC services module. It provides a way to resolve Win32 APIs through gadget in NTDLL's .text section.
072
RastaMouse @rastamouse.me · 02/06/2026
Very cool!
010
RastaMouse @rastamouse.me · 13/05/2026
Created a small .NET tool for ROR13 hashing that you can install to add a global command to cmd/pwsh. It's a lifesaver if you just need some quick hashes.
030
RastaMouse @rastamouse.me · 09/05/2026
No, not pushed yet. Still a few tweaks to be made. This is stock CPL too. Just managing the process state inside the client app.
110
RastaMouse @rastamouse.me · 09/05/2026
I have a new version of the CrystalC2 client that supports BOF cocktails. It's also using the CPL linker sidecar API.
151
RastaMouse @rastamouse.me · 27/04/2026
Built a custom version of Crystal Palace's linkserve. It adds an option to bind to 0.0.0.0 and takes an auth key in the HTTP request. Works great with Docker.
140
RastaMouse @rastamouse.me · 17/04/2026
Having a play with BOF inversions to create atomic test units for detection engineering. Not that I'm a blue teamer of course...
060
RastaMouse @rastamouse.me · 13/04/2026
Very cool
030
RastaMouse @rastamouse.me · 02/04/2026
Now available in the 0.4.0 release. github.com/crystal-c2/c...
010
RastaMouse @rastamouse.me · 01/04/2026
Adding the Crystal Palace YARA generator to CrystalC2. The feedback loop between modifying the .spec, clicking 'build' in the client, and seeing the new rules is super-fast.
040
RastaMouse @rastamouse.me · 26/03/2026
Added initial SOCKS support to CrystalC2. Keeping modularity in mind, the 'extension' needs to be enabled when building a payload. Note that it's the CrystalC2 client that acts as the SOCKS server (rather than the C2 server). Just point tools at your localhost and away you go.
061
RastaMouse @rastamouse.me · 25/03/2026
Got some SOCKS magic working with CrystalC2 but the bigger challenge is how best to implement it. Make it a postex PICO? Expose an option to merge it into the agent at build time? Something else?
141
RastaMouse @rastamouse.me · 23/03/2026
There's some elegance in the simplicity (imo), as it makes them very easy to modify or replace. Here's a view of the agent spec.
020
RastaMouse @rastamouse.me · 23/03/2026
No, I'm currently just packaging a resources directory with the client release.
100
RastaMouse @rastamouse.me · 22/03/2026
Built a C2 optimised for hyprland-style dynamic window tiling (instead of the class tab-approach)
150
RastaMouse @rastamouse.me · 20/02/2026
Working on a small improvement to Crystal Kit - masking heap memory.
060
RastaMouse @rastamouse.me · 09/02/2026
I've been playing with a C2 built around PIC modularity for the last few weeks. C2 comms are merged into the agent at link time and output as shellcode. COFFs are transformed into PICOs for postex. Evasion tradecraft can be woven in via spec files. Very scriptable using Sleep.
172
RastaMouse @rastamouse.me · 01/01/2026
The idea was to merge hooks into a BOF, 'make coff', then run via beacon_inline_execute. I don't think we want to attach the Beacon BOF APIs to funcs within the merged COFF though. What would you attach them to? Can't we just leave/ignore them so Beacon can link them to the proper internal funcs?
120
RastaMouse @rastamouse.me · 01/01/2026
I've written a VSCode extension that provides syntax highlighting for Crystal Palace spec files. I'll throw it up on the marketplace if I can figure out how 😅
050
RastaMouse @rastamouse.me · 31/12/2025
lol nevermind, there were a few mins of 2025 left :D
030
RastaMouse @rastamouse.me · 01/12/2025
lol nailed it
020
RastaMouse @rastamouse.me · 29/11/2025
Pretending to be a blue teamer today
010
RastaMouse @rastamouse.me · 29/11/2025
010
RastaMouse @rastamouse.me · 24/11/2025
I hope Fortra legal don't come after me for this one. I just couldn't resist.
040
RastaMouse @rastamouse.me · 13/11/2025
Postex PICOs <3
030
RastaMouse @rastamouse.me · 11/11/2025
Jumping on the bandwagon
140
RastaMouse @rastamouse.me · 24/10/2025
Did you know that Crystal Palace can merge multiple COFFs straight into a single PIC blob? It means we can produce complete PIC programs from modular parts, without needing a dedicated loader. Plus access to DFR and shared libraries... just lovely.
040
RastaMouse @rastamouse.me · 24/10/2025
I found it far more enjoyable doing string replacements in Aggressor than in the C2 profile because the feedback loop is so much quicker - no need to stop/start the server after every change.
020
RastaMouse @rastamouse.me · 22/10/2025
Took me long enough, but finally managed to hook into mscoreei.dll and stack spoof load library calls for clr.dll.
140
RastaMouse @rastamouse.me · 16/10/2025
Crystal Kit is just too powerful.
040
RastaMouse @rastamouse.me · 13/10/2025
I'm legit blown away. We can use DFR with Nt* APIs now!
061
RastaMouse @rastamouse.me · 05/10/2025
Lovely jubbly
030
RastaMouse @rastamouse.me · 05/10/2025
My motivation behind this is to hook & spoof APIs that aren't supported by BeaconGate, such as CreateProcessA. Passing the PICO memory allocation data to Beacon via BUD also ensures that a custom Sleepmask can free it after ExitThread is called.
100
RastaMouse @rastamouse.me · 04/10/2025
Working on a fun Crystal Palace loader that hooks APIs and pushes them through a call stack spoofing PICO.
182
RastaMouse @rastamouse.me · 13/09/2025
I learned some Java @raphaelmudge.bsky.social !! 😅
030
RastaMouse @rastamouse.me · 12/09/2025
Playing with @raphaelmudge.bsky.social's latest CP update (it's very cool). I have mixed feelings about merging COFFs though. It simplifies overall development and gives the loader fewer jobs to do, but on the other hand you lose some flexibility about where each "part" goes in memory.
161
RastaMouse @rastamouse.me · 31/07/2025
lol amazing. If only I knew of a cool server to join.
000
RastaMouse @rastamouse.me · 24/07/2025
I think I've got a nice way to produce debug builds for Crystal Palace loaders. It produces an EXE that works with WinDbg so you can debug against the source code, with locals, etc.
030