BallisKit provides tooling and services to professional Pentesters & Red Teams. We develop MacroPack, ShellcodePack, and DarwinOps. #redteam #infosec

France
Pinned Tweet
Need to red team macOS targets but don't know where to start? Introducing Mirage C2 🥷! Our new modular, in-memory macOS implant for DarwinOps. Shell, SOCKS proxy, credential & secret extraction, plus private techniques for process injection, privilege escalation, TCC bypass & persistence. From initial access to post-exploitation and EDR evasion, BallisKit now brings the full attack chain to macOS. #RedTeam #macOS
4
9
45
2,167
Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion, private .NET obfuscator, and initial access ! We also started to integrate exploits for vulnerabilities abused in the wild to improve adversary emulation capacity! #redteam
1
6
25
1,716
The new BallisKit tool soon to be released, an advanced macOS Mythic implant! All modular, in memory execution, includes private methods for process injection, TCC bypass, secret grabbing, persistance, malware behavior emulation, EDR Evasion, socks proxy, and more! #redteam #miragen
1
8
34
2,114
RT @EmericNasi: I was thinking maybe releasing a zero day smartscreen bypass with the next version of MacroPack Pro! Only to a limited nb…
82% Do It!
18% Do not do it!
0% Other
17 votes • Final results
5
17
BallisKit retweeted
I've noticed that @bunjavascript has been gaining a lot of traction lately, so I thought it might be interesting to take a look at its offensive potential 🕵️ The game is evolving and we have now entered a new post-exploitation era made of Virtual Machines and Interpreters. Let's revive some old techniques using modern tools ♻️ blog.atsika.ninja/posts/byoi…
24
52
4,530
Learn how to Weaponize Adaptix C2 with MacroPack and ShellcodePack! -> EXE and DLL Sideloading examples -> LNK spoofing PDF, HTA, Clickonce, etc. -> EDR Evasion options #redteam blog.balliskit.com/tutorial-…
23
127
8,908
ShellcodePack just got even better with V2.8.3! Turn shellcode, PE files (.NET, Go, Rust, C/C++), and third-party tooling into deployment-ready payloads with advanced weaponization, multiple output formats, built-in EDR evasion capabilities, and seamless integration with your favorite C2 frameworks. Less time preparing. More time executing. Learn more: balliskit.com/products/shell…
1
13
94
4,971
BallisKit retweeted
Running Sliver from a Word Macro on macOS? Yes it's very easy with the future DarwinOps release! C & Obj-C support , Native ARM64 , JIT-only, Obj-C compatibility, implies full Mythic Poseidon loadability. Word/Excel-embedded JXA execution, no osascript binary involved. #redteam #macos
1
18
62
4,182
BallisKit retweeted
I will be at the "LeHack" conference in Paris with the @BallisKit team end of the week! Ping me if you want to have a chat!
3
4
662
BallisKit retweeted
Introducing EDR Eclipse, our new premium extension for ShellcodePack! EDR Eclipse is an advanced kernel-assisted telemetry suppression module designed to blind the EDR without terminating it. Key capabilities: • Kernel callback removal • Dynamic offset resolution • Telemetry suppression • ETW-TI suppression • Minifilter neutralization Due to the sensitive nature of the technology, availability will be limited to eligible customers. More technical details, demonstrations, and videos are available on the BallisKit Discord! #RedTeam
2
22
107
6,992
BallisKit retweeted
New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events! #redteam
1
11
40
5,555
BallisKit retweeted
We updated our Sliver C2 + BallisKit tutorial to adapt to the latest Sliver version. Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads! More C2 tutorials available on the blog (Adaptix, Mythic) blog.balliskit.com/tutorial-…
18
38
3,298