BallisKit

@balliskit.bsky.social

BallisKit provides tooling and services to professional Pentesters & Red Teams. We develop MacroPack Pro and ShellcodePack. www.balliskit.com

We updated our Sliver C2 + BallisKit tutorial to adapt to the latest Sliver version. Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads! More C2 tutorials available on the blog (Adaptix, Mythic) blog.balliskit.com/tutorial-sli...

Tutorial: Sliver C2 with BallisKit MacroPack and ShellcodePack

In this tutorial, we are going to see how to drop Sliver implants while evading security solutions using BallisKit tooling for Redteam.

blog.balliskit.com

New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events! #redteam

I just wrote a tutorial explaining how to combine Adaptix C2 with MacroPack and ShellcodePack! This provides multiple initial access and EDR evasion options to Adaptix C2 users. Tutorial includes: LNK, CLickOnce, DLL Sideloading, Exe, HTA, etc! #redteam blog.balliskit.com/tutorial-ada...

Tutorial: Adaptix C2 with ShellcodePack and MacroPack

Adaptix C2 is a powerful and popular open source C2 framework. Adaptix gitbook can be found here. Sources are available on Adaptix C2…

blog.balliskit.com

MacroPack new version is out! 🥳 With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario! Also now everything can be leveraged with the new BallisKit GUI! 😎 #redteam

Bild

DarwinOps just leveled up 🚀 Now supports AppleScript (SCPT), a format actively abused for macOS phishing. Plus new Ruby, VSCode , NPM & Homebrew payloads. A true macOS red team Swiss Army knife. AppleScript initial access guide 👇 blog.balliskit.com/macos-redtea...

MacOS Redteam 4: Initial Access with AppleScript

MacOS is often considered well protected, largely due to Gatekeeper. However, some execution vectors still operate under a different trust…

blog.balliskit.com

Tutorial: DLL Sideloading and function proxying with ShellcodePack BallisKit ShellcodePack version 2.8.0 is available! This version comes with a new GUI, EDR evasion methods as well as enhanced DLL sideloading/hijacking. You can find the tutorial here: blog.balliskit.com/tutorial-dll...

Tutorial: DLL Sideloading and function proxying with ShellcodePack

DLL sideloading is a technique that allows an attacker to have a legitimate signed application run some malicious code on Windows. It work…

blog.balliskit.com

We are preparing a new version of ShellcodePack! -> Automated and improved DLL sideloading/proxying capacity -> AppDomain injection -> New Responsive GUI! -> Many more new features And of course up to date EDR evasion :) #shellcodepack

Bild

MacOS red-team made practical — Objective-C implant for DarwinOps! Private Mythic C2 implant: lightweight (in-memory shellcode), post-exploitation, EDR & MDM evasion, integrates with DarwinOps + GateKeeper bypass. Contact us for more details! #RedTeam #macOS

Binary injection vulnerabilities can be found in many MacOS apps. Those may be abused to bypass EDR, hide backdoor, access memory, or bypass TCC! DarwinOps provides - An advanced injection vulnerability scanner - A redteam scenario to exploit them #redteam blog.balliskit.com/macos-dylib-...

macOS DYLIB Injection at Scale: Designing a Self-Sufficient Loader

Let’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection)

blog.balliskit.com

ShellcodePack 2.7.5 is now available! It includes updated bypass profiles for major EDRs We also improved: - ML detection evasion - ETW Patch - CallStack Spoofing ShellcodePack can be used to weaponize any raw shellcode or PE including DotNET, Go, and Rust :) #redteam

Bild

Initial Access on MacOS made easy ! DarwinOps now supports DMG phishing profiles! Those are on shelf realistic templates with Gatekeeper bypass techniques :) This version also introduce a binary injection vulnerability scanner for MacOS! #redteam

Bild

We are adding a binary injection vulnerability scanner to DarwinOps! -> A DarwinOps JXA template -> Scan for Injection vulnerabilities in binaries and Apps Vulnerable binaries could be abused to bypass EDR, hide a backdoor, access memory, or bypass TCC! #redteam

Bild

Here is a reminder that a Powerful DotNET obfuscator is available in MacroPack. Assembly level obfuscation (or course). With the latest 2.7.5 it supports all your favorite #redteam DotNET tools! And tested on major EDRs :) blog.balliskit.com/obfuscation-...

Obfuscation and weaponization of .NET assemblies using MacroPack

For a couple of years now, .NET have been the go to language for a lot of famous offensive security tools like Rubeus, SeatBelt…

blog.balliskit.com

A new version of MacroPack Pro with improved DotNET obfuscator, new shellcode launcher, improved clickonce, and more will be released soon! Also, after Sliver, we a preparing tutorials with Mythic Apollo and Havoc 😎 #redteam

Bild

For us, EDR bypass is not just a buzzword. MacroPack, ShellcodePack, and DarwinOps all come with bypass presets for major EDRs and Antivirus Those presets are regularly updated and tested! If you want to see a demo or an equivalent screenshot for the major EDRs contact us ! #redteam

Bild

Balliskit Evasion Tip 🤖 To help with static analysis detection by EDR, ShellcodePack implements a method to load a shellcode from a separate file or from an URL This tutorial explains how to use that option! #redteam blog.balliskit.com/loading-a-sh...

Loading a shellcode from a file/URL with ShellcodePack

Shellcode in EXE files can sometimes be detected during static analysis, requiring various kinds of obfuscation to bypass EDRs. This…

blog.balliskit.com