Stan Hegt
@stanhacked
Red teamer @ Outflank
ID: 3404758191
https://www.outflank.nl 05-08-2015 21:52:03
296 Tweet
5,5K Followers
157 Following
Let's explore the intricate dance of virtual to physical memory mapping in BYOVD tooling development! π» In Cedric Van Bockhaven's latest blog we delve into resolving addresses using Superfetch, unlocking control over physical memory. Dive into the details now π outflank.nl/blog/2023/12/1β¦
It's not *always* about Windows--macOS and Linux #EDRs need attention, too! In our latest blog, Kyle Avery explains more about the telemetry sources for these under-discussed #endpoint products> outflank.nl/blog/2024/06/0β¦
Here's our new blog on hiding your implant in VTL1, where even an EDR's kernel sensor can't see it.π§βπ¦― Post includes full operational details. Plus our OST offering has been updated with a Cobalt Strike sleep mask exploiting secure enclaves. Full read β‘οΈ outflank.nl/blog/2025/06/1β¦
BOFs are powerful, but error-prone! We dropped a post and new BOF linting tool to catch bugs early, and to prevent crashing implants. This will speed up your Beacon Object File dev workflow. If you're building custom C2 payloads, it's a must-read. π π outflank.nl/blog/2025/06/3β¦
Black Hat Bonus: Learn more about Kyle Avery 's research on training self-hosted LLMs to generate evasive malware and creation of a 7B parameter model that generates evasive Cobalt Strike shellcode loaders able to bypass Microsoft Defender for Endpoint. ow.ly/1EUf50WBI5e