Nate Subra
@natesubra.com
Adversary Simulation, Red Team Lead, Security Research @ LFI Posts are my own He/Him #redteam #offsec #malware #cybersecurity https://secdsm.org I use my real name. The trick is figuring out my handles @natesubra@infosec.exchange
"Some Magic Linker" - a tour of Crystal Palace and TCG. This video demos CPL's features and how they support time-of-use-composition. This enables modular tradecraft & capability recombination. This encourages use/color-agnostic tradecraft, separable from specific capability vimeo.com/1209887681
Some Magic Linker
A feature tour of Crystal Palace.
vimeo.com
My first blog post is up: "Pop a Calc: The Crystal Palace Way" Reinventing msfvenom's Pop a Calc shellcode using Crystal Palace and exploring offensive tradecraft vs capability separation. kerekesha.com/blog/pop-a-c...
Max Kerekesha
Flaneur. Hacker.
kerekesha.com
Just came across this Sleep-hooking UDRL demonstration of Gargoyle using Crystal Palace by WulStack: github.com/WulStack/gar... The above led me to "Gargoyle, a decade later" posted by Josh Lospinoso -- Very philosophical. Worth a read. lospino.so/blog/gargoyl...
Gargoyle, a decade later | Josh Lospinoso
A reflective retrospective on Gargoyle, temporal memory state, the 2026 refresh, and what better validation teaches defenders.
lospino.so
A framework for x64 stack spoofing on Windows. It tackles a complete opposite approach from classic stack spoofing, manipulating unwind metadata to hide arbitrary chunks of the call chain in debuggers and EDRs. github.com/klezVirus/BY... #infosec #cybersecurity #redteam #pentest
GitHub - klezVirus/BYOUD: Bring your own Unwind Data Framework
Bring your own Unwind Data Framework. Contribute to klezVirus/BYOUD development by creating an account on GitHub.
github.com
the fencing visualization system i worked on with rhizomatiks is coming to los angeles this weekend 🤗
Small PIC Energy aff-wg.org/2026/04/13/s... 11th release. JSON-over-HTTP API.
Small PIC Energy
I have a challenge for you: How much beaconing agent functionality can you fit into 4KB PIC? How do you do it? This isn’t a shellcode golf challenge. It’s about elegant ways to build common agent s…
aff-wg.org
You don't need five nines. You don't even need three nines. Go outside.
"emerald-template is a CMake-based project template designed for developing and debugging Reflective DLL Loaders using the Crystal Palace linker." "This allows for source-code level debugging of your loader logic from Windows (and theoretically Linux) systems" github.com/0xTriboulet/...
GitHub - 0xTriboulet/emerald_template: A cmake template for crystal palace
A cmake template for crystal palace. Contribute to 0xTriboulet/emerald_template development by creating an account on GitHub.
github.com
Posting this because I’m not sure Steve is on this platform. He’s made a CLion template for Crystal Palace. github.com/0xTriboulet/...
PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This project demonstrates that It's possible to build a multi-stage and modular C2 implant made of PICOs. github.com/pard0p/PICO-...
GitHub - pard0p/PICO-Implant: PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This project demonstrates that It's possible...
PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This project demonstrates that It's possible to build a multi-stage...
github.com
LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. github.com/pard0p/LibIPC
GitHub - pard0p/LibIPC: LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.
LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. - pard0p/LibIPC
github.com
Blog post about my recent CVE-2025-58726, aka “The Ghost Reflection” is out, read it here: semperis.com/blog/exploit... 🙃
Exploiting Ghost SPNs and Kerberos Reflection for SMB Privilege Elevation
Understanding how attackers use Ghost Service Principal Names to initiate authentication reflection can help you avoid similar vulnerabilities.
semperis.com
LibGate - a Crystal Palace shared library for resolving and performing syscalls github.com/rasta-mouse/...
GitHub - rasta-mouse/LibGate: A Crystal Palace shared library to resolve & perform syscalls
A Crystal Palace shared library to resolve & perform syscalls - rasta-mouse/LibGate
github.com
NTLM relay research is evolving! Join Nick Powers & @tw1sm.bsky.social TOMORROW as they share new methods to enumerate EPA enforcement across MSSQL, HTTP, & more—and intro RelayInformer, expanding attacker-perspective coverage for key protocols. Grab your spot → ghst.ly/oct-web-bsky
And it's released! 🎉 github.com/ofasgard/exe... I've tested it with Rubeus and Seatbelt and a variety of different arguments, and it seems to be pretty stable as far as I can tell. If anyone uses this PICO and encounters bugs or instability, please let me know!
github.com
1 little known secret of help.exe www.hexacorn.com/blog/2025/10...
Pop a vendor website, replace their /.well-known/security.txt with your own rogue contact info, and wait for the bugs to roll in.
MacroPack v2.8.7 is out! New GUI & updated EDR evasion! New features include Advanced LNK spoofing, expanded .NET obfuscation, and ML-evasion. For authorized red-team use! #RedTeam #offensivesecurity
Working on a fun Crystal Palace loader that hooks APIs and pushes them through a call stack spoofing PICO.
Win32_Process has been the go to WMI class for remote command execution for years. Steven Flores explores a new WMI class that functions like Win32_Process and offers further capability. Read more: ghst.ly/4gyPbkr
More Fun With WMI - SpecterOps
TL;DR Win32_Process has been the go to WMI class for remote command execution for years. In this post we will cover a new WMI class that functions like Win32_Process and offers further capability From...
ghst.ly
This report from @interseclab.bsky.social on how a Chinese company is exporting some of the capabilities of "The Great Wall of China" to other autocratic countries is INSANELY INTERESTING: interseclab.org/wp-content/u... *EVERY Page is worth reading* Some interesting tidbits in the thread
interseclab.org
DLL ForwardSideloading www.hexacorn.com/blog/2025/08... using forwarded DLL functions for sideloading purposes
DLL ForwardSideloading, Part 2 www.hexacorn.com/blog/2025/09...
The DSInternals PowerShell module just got an upgrade! 🔥 Updates include: ✅ Golden dMSA Attack ✅ Full LAPS support ✅ Trust password & BitLocker recovery key extraction ✅ Read-only domain controller database compatibility Read more from Michael Grafnetter: ghst.ly/412rZ7F
Juicing ntds.dit Files to the Last Drop - SpecterOps
Discover the latest enhancements to the DSInternals PowerShell module, including the Golden dMSA Attack and support for LAPS, trust passwords, or BitLocker recovery keys.
ghst.ly