Interesting links from the intertubes
20260805
AI-Assisted Vulnerability Research and Offensive Agents
- RAPTOR — Autonomous Offensive and Defensive Security Research Framework
- Journey to Root, Episode I: The Maglev King — Hacking Chrome with AI
- AI-Assisted Vulnerability Research on Embedded Targets
- Building Effective LLM Agents for the AI Cyber Challenge
- Offensive Claude — Spec-Driven Offensive Security Framework for Claude Code
Reverse Engineering, Binary Diffing, and Debugging
- Ghidriff — Ghidra Binary Diffing Engine
- Ghidra RPC — Agentic Reverse-Engineering Skill for Ghidra
- TTDObjectsPy — MCP Server for Microsoft Time Travel Debugging
- KDU — Kernel Driver Utility
- https://truecyber.world/blog/reverse-engineering-toolkit
Exploit Development Training and Tooling
- ARM Exploitation Challenges — Free ARM64 Labs
- CTF Write-Ups and Exploitation Resources
- CorelanTraining — Windows VM Setup Scripts for Corelan Training
- Mona v3 — Corelan’s Exploit-Development Tool for WinDbg
- Red Team Leaders — Cybersecurity Course Catalog
Malware Development, Payloads, and In-Memory Execution
- Pure Malware Development — Resource Collection
- Shellcode: In-Memory Execution of a DLL
- All I Want for Christmas Is Reflective DLL Injection
- Tenebris Gate — Multi-Layer Payload Encryption and Delivery
- RISC-Y Business: Raging Against the Reduced Machine
- CodefromBlog — Code from g3tsyst3m’s Offensive-Security Blog
Cobalt Strike, Loaders, and Modular Tradecraft
- Eden — Modular Cobalt Strike UDRL Proof of Concept
- Dynamically Instrumenting Beacon with BeaconGate for Call-Stack Spoofing
- Modules and Monoliths — Modular Post-Exploitation Tradecraft
- LibTP_Gadget — Thread-Pool Call-Gadget Library for NT API Proxying
- KaplaStrike — Cobalt Strike Reflective Loader Built with Crystal Palace
- Bypassing EDR in a Crystal Clear Way
EDR Evasion and Call-Stack Obfuscation
- Adventures in Dynamic Evasion
- Evading Elastic EDR’s Call-Stack Signatures with Call Gadgets
- Callback Hell: Abusing Callbacks, Tail Calls, and Proxy Frames to Obfuscate the Stack
- Field Notes on Malware: The Evolution of C2 Evasion and What It Means for Detection
Active Directory and Kerberos
Red-Team Operations, References, and Infrastructure
- Red Team Playbooks — Open-Source Notes and Tools
- Red Teaming Toolkit — Open-Source Security Tools for Red Teamers and Threat Hunters
- Safe Red Team Infrastructure
redteam-pentesting.de excellent article on reflection
- Windows Coercion Methods
- Reflective Kerberos Relay Attack
- Reflective Kerberos Relay Attack (PDF)
- wspcoerce (GitHub)
- pretender (GitHub)
- NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073
- The Renaissance of NTLM Relay Attacks: Everything You Need to Know by Elad Shamir
20250617
20250325
- Windows Kernel Pool Memory
- Kernel Callback Removal
- CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)
20250318
20250317
20250311
- Hacking the Xbox 360 Hypervisor Part 1: System Overview
- Hacking the Xbox 360 Hypervisor Part 2: The Bad Update Exploit
- LSA Secrets: revisiting secretsdump
20250306
20250305
- Physmem E: When Kernel Drivers Peek Into Memory
- Red Team Tactics: Combining Direct System Calls and SRDI to Bypass AV/EDR
- Structured Exception Handler x64
- Windows Access Tokens
- How to Write a Local PE Loader from Scratch for Educational Purposes
- Voidgate: How to Execute Shellcode While Keeping It Encrypted
- Hardware Breakpoints
- A Different Take on DLL Hijacking
- Using Syscalls Directly from Visual Studio to Bypass AVs/EDRs
- Living Dangerously with Module Stomping: Leveraging Code Coverage Analysis for Injecting into Legitimately Loaded DLLs
- Kernel Driver Exploit: System Mechanic