44CON is a leading UK cybersecurity conference that brings together security professionals, researchers, and enthusiasts to explore the latest developments in information security. Held at Novotel London West in London, the event features expert-led talks, hands-on workshops, interactive villages, and networking opportunities covering topics such as offensive and defensive security, malware analysis, cryptography, digital forensics, and […]
Read More… from 44Con 2026
GISEC is the Middle East and Africa’s leading cybersecurity event, bringing together cybersecurity professionals, government leaders, technology providers, and industry experts to explore emerging threats, innovative solutions, and the future of digital security. The event offers expert-led sessions, live demonstrations, and valuable networking opportunities.When:September 16-18Where:Dubai, United Arab Emirates. Experts in Attendance: TBD […]
Read More… from GiSec 2026
Introduction This talk will demonstrate how to use Crystal Palace to rapidly develop novel PIC tradecraft/capabilities and immediately deploy them in Cobalt Strike. It will cover novel UDRLs, async BOFs, and async BOF-PEs, and show how Crystal Palace has dramatically lowered the bar for developing novel evasive tradecraft. […]
Read More… from The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike
Introduction This presentation traces the evolution of post-exploitation tradecraft, from executable files and reflective DLLs to in-memory techniques designed to balance capability, developer usability, and operational security. Pieter and Chris examine how detection risks associated with files on disk, PowerShell, foreground execution, and sacrificial processes influenced the development of Beacon Object Files and newer Cobalt […]
Read More… from Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter
Introduction Traditional C2 frameworks often present operators with streams of raw command output spread across multiple implants, making it difficult to retain context, revisit earlier findings, or quickly understand what happened during a long-running engagement. This presentation explores how a C2 teamserver can move beyond unstructured logs by parsing operational data into a searchable, machine-readable […]
Read More… from Modern C2 Teamserver Design with AI-driven Operator Guidance
Introduction While common macOS applications are protected by the hardened runtime, shellcode execution is often still possible because of various entitlements permitting unsigned executable memory. As more applications transition to using the more-restrictive “allow-jit” entitlement, previous execution techniques are rendered ineffective. Execution In this presentation, the speaker examines macOS JIT internals and evaluates public documentation […]
Read More… from macOS Shellcode Execution in JIT Memory
Get RTO and RTO II on a single purchase, at a discounted price. Course, lab access, and exam attempts are all included. Training Content Red Team Operations l 1. Getting Started 2. Law & Compliance 3. Malware Essentials 4. Cobalt Strike Primer 5. Defense Evasion 6. Initial Access 7. Persistence 8. Post-Exploitation 9. Privilege Escalation 10. Elevated […]
Read More… from Red Team Operations I and II
Get the ‘BOF Development & Tradecraft’ and ‘URDL & Sleepmask Development’ courses, created by Alex Reid and Zero-Point Security, in a single purchase, at a discounted price. The BOF Development & Tradecraft course teaches how to write and unit test Beacon Object Files (BOFs) for use in Cobalt Strike and other C2 frameworks. The UDRL […]
Read More… from BOF, UDRL & Sleepmask Development
Hack Glasgow is Scotland’s premier community‑led information security and hacking conference, bringing together security professionals, researchers, enthusiasts, and newcomers for a day of learning, collaboration, and community engagement. The event features multiple speaking tracks, interactive villages, sponsor exhibits, networking opportunities, and an exclusive after‑party, creating an inclusive environment where attendees can explore cybersecurity, privacy, and […]
Read More… from Hack Glasgow 2026
Cobalt Strike 4.13 is now available. This release brings C scripting directly into Cobalt Strike via the new Beacon Interpreter, solves some long-standing issues with BOFs by adding BOF-PE support, and adds a new LLVM Beacon. It also enables centralised management and version control of all exported payloads through the Payload Store, resolves the need […]
Read More… from Cobalt Strike 4.13: Lost In Translation