#Balliskit Tip: You need a way to launch your favorite C2 on the target but you don't know how the dropper can evade the EDR?
MacroPack Pro and ShellcodePack are compatible with all C2! (free and commercial)
And include bypass profiles to help you with that EDR evasion ;)
Demo: Emulate UNC4990 threat actor with MacroPack Pro
This video explains:
- How MacroPack can be used to quickly emulate threat actors initial access methods
- Generate an LNK shellcode launcher (Sliver implant)
- Defender Antivirus bypass
#redteamyoutu.be/tmTb2xqcASs?si…
Just released a new MacroPack version 🥳🥳
For the first time with a GUI! Also includes new bypass methods for LNK payloads, and many more features (DM me or send an email if you want more details)
#redteam#BallisKit
New MacroPack Pro release (2.4.1)! With new HTML smuggling support and focus on LNK shortcuts generation and bypass (tested on multiple AV engines).
#redteam#macropack
Reminder a demo is available here: vimeo.com/746952330
So I am releasing a new tool to help manipulate and weaponize shellcodes. Its called ShellcodePack. Here is a first demo video.
#redteam#shellcodeyoutu.be/d3_dcEKLJbc
MacroPack Pro 2.1.5 is out!
Here is a demo of the persistence feature on an Excel shellcode launcher payload. Notice the AV bypassed on the side.
As usual, only non anonymous professional inquiries are accepted.
#redteam#balliskityoutu.be/6hwfQWsmoes
I wrote this post about writing a stealth VBA RAT in 2016.
blog.sevagas.com/?My-VBA-Bot
Part of it went into MacroPack Pro but I did not release a RAT and C&C itself as there are already a lot of tools available.
However I wonder if someone could need a pure VBA RAT for redteam?
MacroPack Pro Tip: You can spoof your payload file extension with the --unicode-rtlo option
ex: Generate an hta file which appear with png extension in explorer
macro_pack.exe -G _samples\hello.hta -t HELLO --unicode-rtlo=png
To improve my VBA direct syscall code, I integrated a modified version of syswhispers1 to #ShellcodePack to be able to generate shellcode calling syscall in both 64process and also wow64 32bit mode.
In the pic below I generate NtCreateThread VBA to use with #MacroPack Pro.
MacroPack Pro Tip: Classic compiled help files can be trojaned with option -T. And be used to execute any MacroPack template¯o without any warning or confirmation prompt!
See below meterpreter in a malicious DbgView help file.
youtu.be/TOZRWUfGwz4
12K Followers 4K FollowingStarted in ops&blue, now I hack for a living. SANS author/instructor in Oregon. Founder: https://t.co/c36tmCXDpt. He/him.
@[email protected]
3K Followers 33 FollowingBallisKit provides tooling and services to professional Pentesters & Red Teams.
We develop MacroPack, ShellcodePack, and DarwinOps.
#redteam #infosec
9K Followers 813 FollowingPart of Accenture.
IT consulting. We use technology and creativity to turn your ideas into reality
#BCorp #agile #data #cloud #sustainable #product #delivery
5K Followers 422 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
3K Followers 33 FollowingBallisKit provides tooling and services to professional Pentesters & Red Teams.
We develop MacroPack, ShellcodePack, and DarwinOps.
#redteam #infosec
52K Followers 900 FollowingLe moteur de recherche 2.0 !
🇪🇺 Développé et hébergé en Europe
🤖 L’IA pour faire des recherches
🙏 Pas de conservation de l’historique de recherche
5K Followers 422 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
9K Followers 813 FollowingPart of Accenture.
IT consulting. We use technology and creativity to turn your ideas into reality
#BCorp #agile #data #cloud #sustainable #product #delivery
2K Followers 24 FollowingKodewerk is focused on Java pperformance. Using our unique troubleshooting process, we can target and resolve Java performance problems faster.
3K Followers 342 FollowingWorks @ Microsoft, Author of the original Java Performance Tuning Workshop, co-founder #jcreteunconf. All tweets are my own. Mastodon: [email protected]
6K Followers 2K Following⚠️ Vous pouvez suivre toute notre actualité sur le compte
➡️ @PubSapientFR
Engineering Done Right 🚀
@PubSapientFR | @PublicisGroupe 🦁
16K Followers 228 Following🤖 Devoxx France 🤖
Conférence pour les développeurs & développeuses
📍 Paris Palais des Congrès
📆 RDV du 7 au 9 avril 2027 pour la 15ème édition !