Panos Gkatziroulis 🦄 retweeted
I started digging into Win32k callbacks while looking for a PatchGuard bypass. That lead went nowhere, but it raised a better question: how does the Windows kernel choose the callback for session-specific GUI work? idov31.github.io/posts/paint… 1/3
1
23
101
7,441
PyGroup3r - A Python port of Group3r — the Group Policy auditing tool by @mikeloss that authenticates with impacket so it runs from Linux, plus a filterable single-file HTML report on top of the original output formats github.com/S3cur3Th1sSh1t/Py…
4
14
976
Gentle reminder that earlier this year, I published an article containing a full purple team playbook with six procedures for blocking EDR traffic. ✅ Windows Filtering Platform ✅ Hosts File ✅ Routing Table ✅ Name Resolution Policy Table ✅ IPSec Filter Rules ✅ Secondary IP Addresses ipurple.team/2026/01/12/edr-…
EDR traffic and the roadblocks... Windows Firewall COM API to "shape" the traffic originating from the machine. A tool by Jony Schats (@_0xJs_). Source: github.com/0xJs/BlockEDRTraf… #redteam #blueteam
17
66
4,264
InjectSetConsole - Performs process code injection by leveraging a Windows named pipe. Unlike traditional techniques, it does not use the: ✅ VirtualAllocEx & ✅ WriteProcessMemory APIs github.com/TwoSevenOneT/Inje…
4
37
145
7,324
notRDP - A Havoc C2 plugin that creates an invisible alternate Windows desktop, streams it to a browser-based viewer, and supports full mouse/keyboard interaction like RDP, but invisible to the target user github.com/dagowda/notRDP
4
88
427
19,103
🎙️ Earlier this week, I wrote about the Dump Encoding Library case that was disclosed recently. 💭 Are ransomware groups going to use the WerEnc.dll library to perform the encryption in the future? Possibly. The full flow of the technique is displayed below: 🖊️ ipurple.team/2026/09/21/dump…
1
13
1,120