Red Team Operations: Covert Channels and Exfiltration Techniques

This article explores a range of covert communication and exfiltration techniques for Red Team operations, including protocol-level channels, social media, and out-of-band exfiltration techniques.

May 12, 2023 · 12 min · UncleSp1d3r

Advanced Red Team Exercises: Supply Chain Attacks

This article provides an in-depth discussion of advanced red team exercises specifically focused on supply chain attacks, including reconnaissance, weaponization, delivery, exploitation, and post-exploitation phases, with technical details and real-world examples.

April 28, 2023 · 14 min · UncleSp1d3r

SharpSocks: A .NET-Based Proxy for Red Teaming and Network Penetration Testing

SharpSocks is a powerful .NET-based proxy tool for red teaming and network penetration testing that enables encrypted communications, protocol obfuscation, and access to internal resources, providing professional hackers with stealth and persistence in their engagements.

April 15, 2023 · 5 min · UncleSp1d3r

Red Team Exercises: Simulating Real-World Attacks

This article explores the world of red team exercises, discussing various types of exercises, tools and techniques used, real-world examples, and the five phases of a typical red team exercise.

April 14, 2023 · 21 min · UncleSp1d3r

Phishing: Detection and Defeat

A comprehensive guide to advanced phishing evasion techniques for Red Team engagements. Learn infrastructure masking, cloaking, HTML smuggling, and how to bypass automated analysis and Secure Email Gateways.

March 17, 2023 · 5 min · UncleSp1d3r

Memory Corruption 101: Mastering the Buffer Overflow

A comprehensive deep-dive into buffer overflow vulnerabilities. Learn the mechanics of stack frames, master the art of Return-Oriented Programming (ROP), discover how to bypass modern memory protections like ASLR/DEP, and write your first stack-based exploit.

March 14, 2023 · 4 min · UncleSp1d3r

The All-Seeing Eye: Advanced Network Scanning and Enumeration

A comprehensive deep-dive into network scanning and enumeration for red teamers. Master the intricacies of Nmap, explore the power of the Nmap Scripting Engine (NSE), learn advanced evasion techniques, and discover modern high-speed alternatives like RustScan and Masscan.

March 6, 2023 · 14 min · UncleSp1d3r