Red Team Leaders
⌘Ctrlk
Red Team Leaders
  • Welcome
    • Adversary Emulation Guide
    • Red Team Operations Framework
    • Purple Team Operations
    • The first 90 days of a new Red Team
    • Command and Control
    • Defense Evasion
      • Simple Shellcode Runner in Rust
      • Pass the Hash Attack with Mimikatz and PsExec
      • Direct Syscall Execution in Windows
      • Hookchain Technique Introduction by Helvio Júnior (M4v3r1ck)
      • Probabilistic Call Stack: A Deep Dive into Non-Deterministic Execution Paths
      • AMSI Bypass - Neutralizing the Microsoft Antimalware Scan Interface
      • ETW Bypass - Blinding Windows Telemetry
      • Indirect Syscalls — Preserving a Legitimate Stack Trace
      • API Unhooking — Restoring ntdll to a Clean State
      • Process Hollowing — Gutting Legitimate Processes
      • Reflective DLL Injection — DLLs That Load Themselves
      • PPID Spoofing — Forging the Process Tree
      • Token Impersonation — Identity Theft on Windows
      • Shellcode Obfuscation — Hiding Payloads from Static Detection
      • APC Injection — Execution via Asynchronous Procedure Call Queues
      • Heaven's Gate — Calling 64-bit Code from a 32-bit Process
      • Sleep Obfuscation — Encrypting Beacons During Rest
    • Credential Access
    • Windows Internals and API
    • Privilege Escalation
    • Malware Development
    • Initial Access
    • Persistence
  • Offensive Artificial Intelligence
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. OFFENSIVE SECURITY

Defense Evasion

Simple Shellcode Runner in RustPass the Hash Attack with Mimikatz and PsExecDirect Syscall Execution in WindowsHookchain Technique Introduction by Helvio Júnior (M4v3r1ck)Probabilistic Call Stack: A Deep Dive into Non-Deterministic Execution PathsAMSI Bypass - Neutralizing the Microsoft Antimalware Scan InterfaceETW Bypass - Blinding Windows TelemetryIndirect Syscalls — Preserving a Legitimate Stack TraceAPI Unhooking — Restoring ntdll to a Clean StateProcess Hollowing — Gutting Legitimate ProcessesReflective DLL Injection — DLLs That Load ThemselvesPPID Spoofing — Forging the Process TreeToken Impersonation — Identity Theft on WindowsShellcode Obfuscation — Hiding Payloads from Static DetectionAPC Injection — Execution via Asynchronous Procedure Call QueuesHeaven's Gate — Calling 64-bit Code from a 32-bit ProcessSleep Obfuscation — Encrypting Beacons During Rest
PreviousC2 Redirectors Part.1NextSimple Shellcode Runner in Rust