⤷ Title: RingReaper: Stealthy Linux Agent Abuses io_uring to Bypass EDR System Call Monitoring
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 11:28:39 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR Bypass #io_uring #Linux Security #post_exploitation #Red Team #RingReaper #Stealth #System Calls
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 11:28:39 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR Bypass #io_uring #Linux Security #post_exploitation #Red Team #RingReaper #Stealth #System Calls
⤷ Title: RedExt: New Red Team Tool Uses Chrome Extension for Covert Browser Data Exfiltration
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 02:04:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #browser data #Chrome extension #Cybersecurity Tool #Flask C2 #Manifest V3 #post_exploitation #Red Team #RedExt
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 02:04:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #browser data #Chrome extension #Cybersecurity Tool #Flask C2 #Manifest V3 #post_exploitation #Red Team #RedExt
Penetration Testing Tools
RedExt: New Red Team Tool Uses Chrome Extension for Covert Browser Data Exfiltration
RedExt is a new red team framework using a Manifest V3 Chrome extension and a Flask C2 server to covertly exfiltrate and analyze comprehensive browser data for operations.
⤷ Title: DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
Penetration Testing Tools
DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
DCOMRunAs is a covert technique that exploits DCOM and DLL hijacking to execute payloads in the context of a remote, logged-on user's session without new process creation.
⤷ Title: ChromeAlone: Stealthy Browser Implant Steals Sessions and Phishes for YubiKeys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:59:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Browser Implant #ChromeAlone #Credential Theft #EDR Bypass #post_exploitation #Red Team Tool #SOCKS Proxy #WebAuthn Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:59:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Browser Implant #ChromeAlone #Credential Theft #EDR Bypass #post_exploitation #Red Team Tool #SOCKS Proxy #WebAuthn Phishing
Penetration Testing Tools
ChromeAlone: Stealthy Browser Implant Steals Sessions and Phishes for YubiKeys
ChromeAlone is a stealthy browser implant providing EDR-resistant persistence, SOCKS proxying, session/credential theft, and WebAuthn phishing for security tokens.
⤷ Title: Sauron: Fast Active Directory Tool Maps Credential Privileges and Nested Groups in Seconds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:42:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD Enumeration #Credential Context #cybersecurity #Group Policy #LDAP #post_exploitation #Red Team Tool #Sauron
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:42:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD Enumeration #Credential Context #cybersecurity #Group Policy #LDAP #post_exploitation #Red Team Tool #Sauron
Penetration Testing Tools
Sauron: Fast Active Directory Tool Maps Credential Privileges and Nested Groups in Seconds
Sauron is a fast AD tool for post-exploitation. It provides instant context on new credentials, resolving nested groups, OUs, GPO inheritance, and account metadata via LDAP.
⤷ Title: Unmasking Mythic: Kaspersky Reveals How to Detect the Stealthy Open-Source Post-Exploitation Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:18:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 framework #Cobalt Strike #kaspersky #Mythic #Network Detection #open source #post_exploitation #Suricata #UUID
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:18:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 framework #Cobalt Strike #kaspersky #Mythic #Network Detection #open source #post_exploitation #Suricata #UUID
Penetration Testing Tools
Unmasking Mythic: Kaspersky Reveals How to Detect the Stealthy Open-Source Post-Exploitation Framework
Researchers at Kaspersky Lab have published an in-depth study on how to detect the presence of Mythic within
⤷ Title: Silent Pivot: Exploiting SpeechRuntimeMove for Stealthy Lateral Movement via DCOM
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:57:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM Hijacking #DCOM #DLL Sideloading #Lateral Movement #post_exploitation #red teaming #Remote Registry #SpeechRuntime #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:57:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM Hijacking #DCOM #DLL Sideloading #Lateral Movement #post_exploitation #red teaming #Remote Registry #SpeechRuntime #Windows Security
Penetration Testing Tools
Silent Pivot: Exploiting SpeechRuntimeMove for Stealthy Lateral Movement via DCOM
SpeechRuntimeMove abuses DCOM and COM hijacking to execute code in an active user's session, bypassing the need for a full system takeover.
⤷ Title: The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
Information Security News
The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
Threat actors have begun repurposing a legitimate server monitoring tool as a ready-made platform for remotely controlling systems that have already been compromised. According to the Ontinue Cybe…
⤷ Title: The Ghost in the Machine: Master Stealth with the Orsted C2 Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:44:26 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Evasion #Command and Control #cybersecurity #Go_lang #Ligolo_ng #Orsted C2 #Penetration Testing #post_exploitation #red teaming #Sandbox Deception
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:44:26 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Evasion #Command and Control #cybersecurity #Go_lang #Ligolo_ng #Orsted C2 #Penetration Testing #post_exploitation #red teaming #Sandbox Deception
Penetration Testing Tools
The Ghost in the Machine: Master Stealth with the Orsted C2 Framework
Orsted C2 is a modular Go framework featuring sandbox deception, AMSI/ETW evasion, and native Ligolo-ng pivoting for advanced red team simulations.
⤷ Title: The Nim Shadow: Conquest C2 Redefines Stealth for 2026 Red Teams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:47:54 +0000
════════════════════════
⌗ Tags: #Open Source Tool #adversary simulation #Conquest C2 #Dear ImGui #evasion techniques #InfoSec 2026 #Monarch Agent #Nim Programming #Penetration Testing #post_exploitation #red teaming
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:47:54 +0000
════════════════════════
⌗ Tags: #Open Source Tool #adversary simulation #Conquest C2 #Dear ImGui #evasion techniques #InfoSec 2026 #Monarch Agent #Nim Programming #Penetration Testing #post_exploitation #red teaming
Information Security News
The Nim Shadow: Conquest C2 Redefines Stealth for 2026 Red Teams
Conquest is a feature-rich, extensible and malleable command & control/post-exploitation framework developed for penetration testing and adversary simulation. Conquest’s team server, ope…