Chromeo: Offensive Tradecraft for In-browser Operations

Introduction Modern browser-based operations are changing as Chromium introduces new protections designed to reduce cookie theft and session hijacking. This presentation explores the Chromeo tooling in OST. In it we discuss how Chrome DevTools Protocol (CDP) can be enabled within an already running Chromium-based browser, bypassing traditional command-line flag requirements and overcoming restrictions that limit […]

Read More… from Chromeo: Offensive Tradecraft for In-browser Operations

The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike

Introduction This talk will demonstrate how to use Crystal Palace to rapidly develop novel PIC tradecraft/capabilities and immediately deploy them in Cobalt Strike. It will cover novel UDRLs, async BOFs, and async BOF-PEs, and show how Crystal Palace has dramatically lowered the bar for developing novel evasive tradecraft. […]

Read More… from The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike

Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter

Introduction This presentation traces the evolution of post-exploitation tradecraft, from executable files and reflective DLLs to in-memory techniques designed to balance capability, developer usability, and operational security. Pieter and Chris examine how detection risks associated with files on disk, PowerShell, foreground execution, and sacrificial processes influenced the development of Beacon Object Files and newer Cobalt […]

Read More… from Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter

Modern C2 Teamserver Design with AI-driven Operator Guidance

Introduction Traditional C2 frameworks often present operators with streams of raw command output spread across multiple implants, making it difficult to retain context, revisit earlier findings, or quickly understand what happened during a long-running engagement. This presentation explores how a C2 teamserver can move beyond unstructured logs by parsing operational data into a searchable, machine-readable […]

Read More… from Modern C2 Teamserver Design with AI-driven Operator Guidance

macOS Shellcode Execution in JIT Memory

Introduction While common macOS applications are protected by the hardened runtime, shellcode execution is often still possible because of various entitlements permitting unsigned executable memory. As more applications transition to using the more-restrictive “allow-jit” entitlement, previous execution techniques are rendered ineffective. Execution In this presentation, the speaker examines macOS JIT internals and evaluates public documentation […]

Read More… from macOS Shellcode Execution in JIT Memory

Cobalt Strike Technical Demo

Watch a technical walkthrough of Cobalt Strike’s advanced capabilities for post-exploitation and adversary simulation, or our new Cobalt Strike Research Labs. In the session, Cobalt Strike developers and researchers will demonstrate usage of the product and show the advanced evasion and customization of Cobalt Strike through hands-on demos. The session will be presented by Cobalt […]

Read More… from Cobalt Strike Technical Demo