Antoine (@antoinedss) 's Twitter Profile
Antoine

@antoinedss

Working at @balliskit as a macOS offensive developer. Tweets are my own.

ID: 1762144905940312064

calendar_today26-02-2024 15:58:10

8 Tweet

27 Followers

49 Following

Emeric Nasi (@emericnasi) 's Twitter Profile Photo

Good News my RedTeam friends! New BallisKit tool to target MacOs: DarwinOps 😎 Features: - On shelf initial access scenarios - Multiple formats - Obfuscation methods and EDR bypass options - Privilege escalation and persistence - Compatible with several C2 #redteam

Good News my RedTeam friends!

New BallisKit tool to target MacOs:
DarwinOps 😎

Features:
 - On shelf initial access scenarios
 - Multiple  formats
 - Obfuscation methods and EDR bypass options
 - Privilege escalation and persistence 
 - Compatible with several C2  
 
 #redteam
BallisKit (@balliskit) 's Twitter Profile Photo

Redteaming on MacOS is hard... But BallisKit can help you! You can use DarwinOps to weaponize a Mythic C2 implant for MacOS and bypass EDRs! Checkout this blog Post by Antoine #redteam blog.balliskit.com/setup-and-weap…

BallisKit (@balliskit) 's Twitter Profile Photo

Bypassing EDRs on MacOS can be a challenge. In our new blog post, Antoine describes how EDRs leverage MacOS Network Extension to detect C2s and how to bypass this kind of detection using Mythic Apfell as an example. #redteam blog.balliskit.com/when-osascript…

Antoine (@antoinedss) 's Twitter Profile Photo

Getting into the mindset of a defensive security developer has been much easier than diving into pure reverse engineering. There’s still a lot of ground to cover and many potential bypasses to explore when it comes to EDRs on macOS.

Atsika (@_atsika) 's Twitter Profile Photo

ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒 🌐 github.com/quarkslab/prox… Blog post for more details right below ⬇️

BallisKit (@balliskit) 's Twitter Profile Photo

MacOS security is very different from Windows. DarwinOps, our redteam tool targeting MacOS can help you tackle that issue! Antoine just posted on our blog to help you understand the basics of initial access on MacOS with DarwinOps #redteam blog.balliskit.com/macos-initial-…

BallisKit (@balliskit) 's Twitter Profile Photo

We are adding a binary injection vulnerability scanner to DarwinOps! -> A DarwinOps JXA template -> Scan for Injection vulnerabilities in binaries and Apps Vulnerable binaries could be abused to bypass EDR, hide a backdoor, access memory, or bypass TCC! #redteam

We are adding a binary injection vulnerability scanner to DarwinOps!
 -> A DarwinOps JXA template
 -> Scan for Injection vulnerabilities in binaries and Apps
 
Vulnerable binaries could be abused to bypass EDR, hide a backdoor, access memory, or bypass TCC!
 
 #redteam
BallisKit (@balliskit) 's Twitter Profile Photo

MacOS DMG phishing templates are coming in the next DarwinOps release! Ready to use, configurable, and with new GateKeeper bypass strategies! #redteam

MacOS DMG phishing templates are coming in the next DarwinOps release! 
Ready to use, configurable, and with new GateKeeper bypass strategies!

#redteam