Introduction Modern browser-based operations are changing as Chromium introduces new protections designed to reduce cookie theft and session hijacking. This presentation explores the Chromeo tooling in OST. In it we discuss how Chrome DevTools Protocol (CDP) can be enabled within an already running Chromium-based browser, bypassing traditional command-line flag requirements and overcoming restrictions that limit […]
Read More… from Chromeo: Offensive Tradecraft for In-browser Operations
Introduction AI is changing how red teams work, and it’s an open question how far that goes. On the one hand, there is a future where we let an AI loose with a prompt like, ‘hack this environment like APT29.’ On the other, red teaming often involves access into core production systems where there is […]
Read More… from No Turning Back: Practical Ideas on Embedding AI in Red Team Ops
Introduction This talk will demonstrate how to use Crystal Palace to rapidly develop novel PIC tradecraft/capabilities and immediately deploy them in Cobalt Strike. It will cover novel UDRLs, async BOFs, and async BOF-PEs, and show how Crystal Palace has dramatically lowered the bar for developing novel evasive tradecraft. […]
Read More… from The Game Has Changed: Rapid PIC Development with Crystal Palace and Cobalt Strike
Introduction This presentation traces the evolution of post-exploitation tradecraft, from executable files and reflective DLLs to in-memory techniques designed to balance capability, developer usability, and operational security. Pieter and Chris examine how detection risks associated with files on disk, PowerShell, foreground execution, and sacrificial processes influenced the development of Beacon Object Files and newer Cobalt […]
Read More… from Post-Ex Evolution: From Back Orifice to Cobalt Strike’s interpreter
Introduction Traditional C2 frameworks often present operators with streams of raw command output spread across multiple implants, making it difficult to retain context, revisit earlier findings, or quickly understand what happened during a long-running engagement. This presentation explores how a C2 teamserver can move beyond unstructured logs by parsing operational data into a searchable, machine-readable […]
Read More… from Modern C2 Teamserver Design with AI-driven Operator Guidance
Introduction While common macOS applications are protected by the hardened runtime, shellcode execution is often still possible because of various entitlements permitting unsigned executable memory. As more applications transition to using the more-restrictive “allow-jit” entitlement, previous execution techniques are rendered ineffective. Execution In this presentation, the speaker examines macOS JIT internals and evaluates public documentation […]
Read More… from macOS Shellcode Execution in JIT Memory
Cobalt Strike 4.12 introduces: Release blogs can be found here and release notes here. Are you ready to take the next step? […]
Read More… from Cobalt Strike 4.12 in 1 Minute
Watch a technical walkthrough of Cobalt Strike’s advanced capabilities for post-exploitation and adversary simulation, or our new Cobalt Strike Research Labs. In the session, Cobalt Strike developers and researchers will demonstrate usage of the product and show the advanced evasion and customization of Cobalt Strike through hands-on demos. The session will be presented by Cobalt […]
Read More… from Cobalt Strike Technical Demo
Watch a technical walkthrough of Fortra’s Outflank Security Tooling portal. The session will be presented by red team experts Marc Smeets and Stan Hegt of Outflank. Incorporate Outflank into your red team engagements […]
Read More… from Outflank Technical Demo
This short video provides a high level overview on how to install and use the Cobalt Strike Mutator Kit, which uses an LLVM obfuscator to break in-memory YARA scanning of the sleep mask. Are you ready to take the next step? […]
Read More… from Mutator Kit: Cobalt Strike Feature Demo