RastaMouse

@rastamouse.me

make pic +relax

The gap between “academic cyber labs” and real-world red teaming is shrinking. Students can now train with licensed Cobalt Strike and Zero Point Security’s Red Team Ops, built around real adversary emulation, not abstractions. This is how you teach modern offensive security.

Bild

MSF's Railgun was massively underrated but incredibly powerful. Resolve and call an API without needing to alloc and run a whole BOF or DLL. I hope to get this implemented nicely in CrystalC2 at some point.

Bild

New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the @specterops.io GhostWorks initiative. Can't wait to show what we've been working on! specterops.io/blog/2026/06...

Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA

Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.

specterops.io

CS 4.13 is right around the corner, so I've been having a play with the new Beacon Interpreter. This script will stomp a PICO over a module, with unwind data, for post-ex.

Bild

Pushed 0.0.3 of my Crystal Palace VSC extension. It adds new +options, like +relax and +unwind; and adds better syntax support for the ised command.

Bild

New Release: Havoc Professional 0.7 K-Noir 🐺 New Linux implant for x86_64 and AArch64, Stack Spoofing related improvments such as CET compliance and a function rule system, new registry manipulation extension and injection based capabilities. Link: www.infinitycurve.org/blog/k-noir

Havoc Professional 0.7: K-Noir

An introduction to Havoc Professional 0.7 K-Noir, featuring a new Linux implant for x86_64 and AArch64, CET compliant stack spoofing and rules systems, new Direct and P2P communication channels, new m...

infinitycurve.org

I had the occasion to play with EAF the other day, so I added a bypass to the TCG's PIC services module. It provides a way to resolve Win32 APIs through gadget in NTDLL's .text section.

Bild