Skip to main content

Tools

BloodHound: Analyzing Active Directory for Security Risks and Attack Paths

··1695 words·8 mins
BloodHound is a powerful tool for analyzing Active Directory environments, helping red teamers and pen testers visualize complex relationships, identify security risks and attack paths, and develop effective mitigation strategies to strengthen an organization’s security posture.

Mythic: the plug-in C2 framework that ate Cobalt Strike's open-source competition

··2100 words·10 mins
A working tour of Cody Thomas’s Mythic C2 framework. Architecture (Docker-deployed server plus pluggable agents and C2 profiles), the actual current agent lineup in 2026 (Apollo, Poseidon, Apfell, Athena, Xenon, Medusa, Thanatos, Freyja, Sage), the install workflow with mythic-cli, how Mythic compares to Sliver, Cobalt Strike, and Havoc, and where it fits in a modern engagement stack.

Covenant: a .NET C2 framework worth learning even after deprecation

··3045 words·15 mins
A working tour of Ryan Cobb’s Covenant C2 framework from an operator’s perspective. Architecture (server, Grunts, listeners, dynamically compiled .NET tasks), AMSI and ETW patching as a survival prerequisite on modern Windows, SMB named-pipe P2P routing for jumping into segmented zones, Donut shellcode wrapping for non-.NET payloads, and writing custom tasks. Covenant is effectively unmaintained, but the design choices it pioneered are still in Sliver, Mythic, and Havoc.

Nishang in 2026: useful, dated, and still in Kali

··1722 words·9 mins
A working operator’s view of Nishang, the PowerShell post-exploitation toolkit Nikhil Mittal built starting in 2012. What it does well, where Defender catches it on sight in 2026, which modules still matter, and how it fits with modern frameworks (Empire 5.x, Sliver, Mythic). Plus an operator-honest read on AMSI and Constrained Language Mode and what they leave behind for stock PowerShell tools on a current Windows endpoint.

Empire: the open-source C2 that taught a generation

··1428 words·7 mins
A working tour of the BC Security Empire fork in 2026. Listeners, stagers, and the four agent types Empire ships today (PowerShell, Python, IronPython, and Sharpire/C#). Plus an honest read on where Empire still earns its keep in 2026, where Sliver and Havoc have eaten its lunch, and what AMSI evasion actually looks like now that Defender has shipped signatures for the obvious bypasses.

Password cracking: infrastructure, wordlists, and rules

··1324 words·7 mins
A working operator’s view of password cracking past rockyou.txt. Building a dedicated GPU rig (and when to burst to cloud), tuning Hashcat for fast and slow hash types, generating context-specific wordlists with CeWL and PRINCE, and writing rules that target how humans actually compose passwords inside an enterprise.

The Swiss Army Knife of Exploitation: Mastering the Metasploit Framework

··2689 words·13 mins
A working operator’s guide to Metasploit. Covers the module taxonomy, why you actually want the database initialized, staged vs non-staged payloads and when each one matters, Meterpreter’s load-bearing extensions (stdapi, kiwi, incognito, priv), pivoting (autoroute, portfwd, SOCKS), and resource scripts for the listener setup you’d otherwise type a hundred times an engagement.

PsExec: The Double-Edged Sword of Remote Execution

··884 words·5 mins
A deep-dive into PsExec for offensive work. How it works under the hood, how to leverage pass-the-hash with Impacket, service-name evasion, and the forensic footprint it leaves so you know when to reach for it and when to reach for something else.

Mastering sc.exe: Remote Service Execution

··1107 words·6 mins
A deep-dive into sc.exe for offensive work. Weaponize the Windows Service Control Manager for remote code execution, persist via service failure actions, exploit weak service ACLs, and load kernel drivers.

Silent Interrogator: WMIC for Red Teaming

··907 words·5 mins
A deep-dive into Wmic for offensive work. Interrogate system internals, move laterally, find security software, abuse XSL transforms for code execution, and understand the forensic footprint WMI leaves behind.

Living off the Land: Windows CLI for Red Teams

··642 words·4 mins
A comprehensive deep-dive into advanced Windows command-line tools. Learn how to leverage modern binaries like curl and tar, abuse legacy tools for download and execution, and perform stealthy data theft and persistence without triggering alerts.

Chisel: The Stealthy Architect of Network Tunnels

··1172 words·6 mins
A practical walkthrough of Chisel for tunneling — reverse SOCKS, port forwarding, TLS hardening with a real cert, source-level evasion tweaks, and how it compares to Ligolo-ng.

xfreerdp & Passthe-Hash: RDP Techniques

··1160 words·6 mins
How Pass-the-Hash actually works against RDP — what makes it normally fail, why Restricted Admin Mode flips that around, the correct xfreerdp syntax, RDP-over-SOCKS tuning, and the Logon Type 3 anomaly that gives the technique away.

Mastering the Maze: Advanced Tunneling and Port Redirection for Red Team Operators

··1540 words·8 mins
A working guide to network tunneling for offensive ops — iptables NAT, every flavor of SSH forwarding (including reverse SOCKS and ProxyJump), Windows netsh portproxy, socat, and the modern compiled tools that have largely replaced everything else (Chisel and Ligolo-ng).

Master the Database - Exploiting Microsoft SQL Server with Impacket

··1210 words·6 mins
A red team walkthrough of Impacket’s mssqlclient.py — discovery, every common auth method, RCE via xp_cmdshell / OLE Automation / CLR, hash capture via xp_dirtree, linked-server hops, file transfer over TDS, and finding the data that actually matters.

Master SMB Operations - Using Impacket to Conquer Windows Shares

··1421 words·7 mins
A walkthrough of Impacket’s SMB tooling for offensive work — smbclient.py, smbserver.py, secretsdump.py, and ntlmrelayx.py. Covers Pass-the-Hash, hash capture via UNC paths, DCSync, and cross-protocol NTLM relay.

smbclient: Red Team Guide to SMB

··1830 words·9 mins
A long walkthrough of smbclient for offensive work — SMB dialects, enumeration, bulk exfiltration, Pass-the-Ticket via Kerberos, opsec around credentials, and what the blue team sees when you connect.

Install Impacket: Complete Red Team Guide

··1040 words·5 mins
A comprehensive guide to installing and mastering Impacket, covering installation via pipx, deep dives into core tools, and advanced authentication attacks.