The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike

Introduction This talk will demonstrate how to use Crystal Palace to rapidly develop novel PIC tradecraft/capabilities and immediately deploy them in Cobalt Strike. It will cover novel UDRLs, async BOFs, and async BOF-PEs, and show how Crystal Palace has dramatically lowered the bar for developing novel evasive tradecraft. […]

Read More… from The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike

Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter

Introduction This presentation traces the evolution of post-exploitation tradecraft, from executable files and reflective DLLs to in-memory techniques designed to balance capability, developer usability, and operational security. Pieter and Chris examine how detection risks associated with files on disk, PowerShell, foreground execution, and sacrificial processes influenced the development of Beacon Object Files and newer Cobalt […]

Read More… from Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter

Modern C2 Teamserver Design with AI-driven Operator Guidance

Introduction Traditional C2 frameworks often present operators with streams of raw command output spread across multiple implants, making it difficult to retain context, revisit earlier findings, or quickly understand what happened during a long-running engagement. This presentation explores how a C2 teamserver can move beyond unstructured logs by parsing operational data into a searchable, machine-readable […]

Read More… from Modern C2 Teamserver Design with AI-driven Operator Guidance

macOS Shellcode Execution in JIT Memory

Introduction While common macOS applications are protected by the hardened runtime, shellcode execution is often still possible because of various entitlements permitting unsigned executable memory. As more applications transition to using the more-restrictive “allow-jit” entitlement, previous execution techniques are rendered ineffective. Execution In this presentation, the speaker examines macOS JIT internals and evaluates public documentation […]

Read More… from macOS Shellcode Execution in JIT Memory

Cobalt Strike Technical Demo

Watch a technical walkthrough of Cobalt Strike’s advanced capabilities for post-exploitation and adversary simulation, or our new Cobalt Strike Research Labs. In the session, Cobalt Strike developers and researchers will demonstrate usage of the product and show the advanced evasion and customization of Cobalt Strike through hands-on demos. The session will be presented by Cobalt […]

Read More… from Cobalt Strike Technical Demo

Cobalt Strike In 5 Minutes

Cobalt strike is a powerful red team tool that is used by pen testers and red teamers to replicate the tactics and techniques of long-term embedded attackers. This 5-minute video will give you a high-level overview of Cobalt Strike’s functionality, including its signature payload, Beacon, and its flexible C2 framework. Are you ready to take the next step? […]

Read More… from Cobalt Strike In 5 Minutes