3 Followers
1 Following
17 Posts
BallisKit provides tooling and services to professional Pentesters & Red Teams.
BallisKit develops the pro edition of MacroPack.
Our websitehttps://www.balliskit.com
Our LinkedIn pagehttps://www.linkedin.com/company/balliskit/
#ShellcodePack tip: Some of the advanced emulator bypass techniques presented by @EmericNasi
at TyphoonCon are implemented in the current version of ShellcodePack.
MacroPack Tip: Reproducing adversary methods such as Zip -> vbs -> payload.dll + decoy.pdf (without parent/child process relations) is done with a single command line. You can also use the GUI to build that command line.
#redteam
MacroPack Pro tip: Need originality? You can generate all kinds of less common formats payloads. Such as Visio, MS PROJECT, HTA, SCT, LNK, SyLK, CHM, CSPROJ, OneNote, etc.
#redteam #infosec
MacroPack Pro Tip : Remember MacroPack Pro has an option to automatically create the payload in a container such as an ISO volume, Zip, and HTML smuggling. Ex: Put payload in a zip file itself inside an HTML smuggling file: --container=http://name.zip.html
Or use the GUI
#RedteamTools
Happy new year to all our followers!
MacroPack GUI in Beta version is ready. For our existing customers wanting to test it, please reach out on the Slack group or by email.
#redteam #infosec
#BallisKit tip: Have you tried using CPL for your payloads? Generate a CPL shellcode launcher with various bypass options with ShellcodePack!
Use the next command line or the GUI:
shellcode_pack -i sc.bin -G test.cpl --bypass
#redteam