BallisKit provides tooling and services to professional Pentesters & Red Teams.
We develop MacroPack, ShellcodePack, and DarwinOps.
#redteam #infosecballiskit.com FranceJoined June 2020
Running Sliver from a Word Macro on macOS? Yes it's very easy with the future DarwinOps release!
C & Obj-C support , Native ARM64 , JIT-only, Obj-C compatibility, implies full Mythic Poseidon loadability. Word/Excel-embedded JXA execution, no osascript binary involved.
#redteam#macos
Introducing EDR Eclipse, our new premium extension for ShellcodePack!
EDR Eclipse is an advanced kernel-assisted telemetry suppression module designed to blind the EDR without terminating it.
Key capabilities:
• Kernel callback removal
• Dynamic offset resolution
• Telemetry suppression
• ETW-TI suppression
• Minifilter neutralization
Due to the sensitive nature of the technology, availability will be limited to eligible customers.
More technical details, demonstrations, and videos are available on the BallisKit Discord!
#RedTeam
New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events!
#redteam
We updated our Sliver C2 + BallisKit tutorial to adapt to the latest Sliver version.
Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads!
More C2 tutorials available on the blog (Adaptix, Mythic)
blog.balliskit.com/tutorial-slive…
LNK is still a top-tier initial access vector. Most defenses still underestimate it.
Soon to be released MacroPack 2.8.9 pushes LNK tradecraft further:
• Advanced customization & evasion workarounds
• Improved EDR bypass
• Several delivery alternatives
Version also contains other features such as VHDX container, new .NET shellcode injection, etc.
Built from real-world testing against modern EDRs.
#RedTeam
I just wrote a tutorial explaining how to combine Adaptix C2 with MacroPack and ShellcodePack! This provides multiple initial access and EDR evasion options to Adaptix C2 users.
Tutorial includes: LNK, CLickOnce, DLL Sideloading, Exe, HTA, etc!
#redteamblog.balliskit.com/tutorial-adapt…
@du3kkk0 The contact email must come from a company domain and the email must mention your name & company. We do not accept emails likg gmail/outlook etc. Only official company/organization email addresses.
The next ShellcodePack version supports AppDomain injection payloads! We also simplified and improved DLL sideloading/proxying and updated the EDR bypass profiles.
Sideload anything with a few clicks! 😎
#redteam
Using #darwinOps, after setting up your redteam scenario, you can choose which phishing template will be most convincing for your engagement 😎
Contact us to know more about redteaming on macOS and ready to use phishing templates!
#redteam
MacroPack new version is out! 🥳
With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario!
Also now everything can be leveraged with the new BallisKit GUI! 😎
#redteam
27K Followers 1K FollowingSenior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
5K Followers 422 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
30K Followers 821 FollowingCyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
687 Followers 2K FollowingCreator behind @CineTrakApp - A movie and TV show tracking and discovery app https://t.co/a5jOME4TVQ - ◽️Infosec ◽️Videogames ◽️Tech ◽️Music
30 Followers 450 FollowingBoniventure Yohana Salumu | Cybersecurity Specialist & Digital Forensics Engineer. Known online as Bundala De Hacker. Specialized in Red Teaming (CRTA, AD-RTS)
5K Followers 422 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
30K Followers 821 FollowingCyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
8K Followers 6K Following#InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
3K Followers 2K FollowingFishing, hiking, photography, music, & cigars.
Principal Consultant @RedSiege so I can pay for my hobbies. @hardwaterhacker.bsky.social
6K Followers 2K FollowingBack to Red Teaming. Risk Hunter. DEFCON Staff & CFP Board. MS in DF. Fmr Fire/EMS. Red and Blue. Builder. Morally Flexible. https://t.co/zakkIXeyHu @ bluesky
16K Followers 2 FollowingConsultancy and Training for offensive security by trusted experts | https://t.co/HtHSYcDxoK | https://t.co/UvOhGA5xe2 | @nighthawk_c2
14K Followers 2K FollowingTeam @hashcat! Eternal n00b and knowledge seeker! Age is just a number and motivation is the fuel!
Whatever you do in your life, do not forget to be humble.
28K Followers 1 FollowingOffensiveCon is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #Offensivecon #Tokyo.