<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>RWXStoned</title>
    
    
    <link>https://rwxstoned.github.io/</link>
    <atom:link href="https://rwxstoned.github.io/feed.xml" rel="self" type="application/rss+xml" />
    
    
      <item>
        <title>Using Slack links-preview to smuggle C2 in locked-down environments.</title>
        <description>
          (even when Slack traffic is restricted to your corporate workspace) - 
          Detecting and blocking anomalous web requests has become trivial for Blue Teams, and if you are on a red team engagement, an implant pinging constantly to mybrandnewdomain-about-cooking.lol will not fly nowadays. Using External C2 has become one of the more...
        </description>
        <pubDate>Thu, 18 Jun 2026 00:00:00 -0400</pubDate>
        <link>https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/</guid>
      </item>
    
      <item>
        <title>My Beacon 2025 Talk on User-Defined Reflective Loader</title>
        <description>
          A friendly intro to Cobalt Strike&apos;s UDRL - 
          I had the pleasure of giving this talk a London Beacon 2025 conference earlier this year and here are the slides: A friendly intro to Cobalt Strike’s UDRLs The aim was to try to give some documentation on how Cobalt...
        </description>
        <pubDate>Wed, 19 Nov 2025 00:00:00 -0500</pubDate>
        <link>https://rwxstoned.github.io/2025-11-19-beacon-UDRL-intro/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2025-11-19-beacon-UDRL-intro/</guid>
      </item>
    
      <item>
        <title>My x33fcon 2025 Talk on Code Injection</title>
        <description>
          Taming the Windows Loader for Stealthy Injection - 
          This is the link to my x33fcon 2025 Talk this year: Taming the Windows Loader for Stealthy Injection The Github page associated to that technique contains some technical data illustrating what I am talking about, and the slides are available...
        </description>
        <pubDate>Tue, 09 Sep 2025 00:00:00 -0400</pubDate>
        <link>https://rwxstoned.github.io/2025-09-09-x33fcon/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2025-09-09-x33fcon/</guid>
      </item>
    
      <item>
        <title>Making the Debugging of UDRLs (a bit) Easier</title>
        <description>
          a simple addition to the UDRL-VS framework to enable the logging of debug strings in your loader at runtime - 
          The introduction of this Visual Studio project as a template for building Cobalt Strike UDRL has come with a lot of little gimmicks aimed at making your life a bit easier as a malware developer. Developing Position Independant Code (PIC)...
        </description>
        <pubDate>Sun, 06 Jul 2025 00:00:00 -0400</pubDate>
        <link>https://rwxstoned.github.io/2025-07-06-Better-debugging-UDRL/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2025-07-06-Better-debugging-UDRL/</guid>
      </item>
    
      <item>
        <title>How is my Browser blocking RWX execution ?</title>
        <description>
          reviewing an EDR-like mechanism implemented by a popular browser - 
          EDIT January 10, 2025 [ Aaron Klotz (@dblohm7), an ex-Mozilla developer, reached out to me to explain that he worked on this in an effort to prevent third-party software from messing with Firefox (which was often the case, mostly via...
        </description>
        <pubDate>Sat, 04 Jan 2025 00:00:00 -0500</pubDate>
        <link>https://rwxstoned.github.io/2025-01-04-Reviewing-browser-hooks/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2025-01-04-Reviewing-browser-hooks/</guid>
      </item>
    
      <item>
        <title>Introducing GimmeShelter.py</title>
        <description>
          a situational awareness Python script to help you find where to put your beacons - 
          GimmeShelter.py is a lightweight Python script which will help you get a good view of what a Windows environment looks like, and highlight opportunities for hiding/running malware from unusual modules, or memory setups. Situational Awareness Once on a host, a...
        </description>
        <pubDate>Fri, 06 Dec 2024 00:00:00 -0500</pubDate>
        <link>https://rwxstoned.github.io/2024-12-06-GimmeShelter/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2024-12-06-GimmeShelter/</guid>
      </item>
    
      <item>
        <title>BeaconGate, Sleepmask... customizing Cobalt Strike after 4.10</title>
        <description>
          a quick new Sleep PoC using the latest Cobalt Strike features - 
          Cobalt Strike keeps on evolving and this has serious implications on what happens behind the scenes when your payload runs, and what the resulting IOCs will be. With the growing complexity of the product there has also been a lot...
        </description>
        <pubDate>Wed, 13 Nov 2024 00:00:00 -0500</pubDate>
        <link>https://rwxstoned.github.io/2024-11-13-Cobalt-Strike-customization/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2024-11-13-Cobalt-Strike-customization/</guid>
      </item>
    
      <item>
        <title>An RTO2 Review</title>
        <description>
          A great (and cheap) cert from ZeroPoint Security - 
          This is my review of the CRTL training from ZeroPoint Security, and incidentally, of the Elastic EDR, which is the solution used in the course and its lab. The CRTL (or RTO2) is a fairly new certification following-up on RTO...
        </description>
        <pubDate>Thu, 07 Nov 2024 00:00:00 -0500</pubDate>
        <link>https://rwxstoned.github.io/2024-11-07-RTO2-review/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2024-11-07-RTO2-review/</guid>
      </item>
    
      <item>
        <title>MANDIANT CAPA for Red Teams</title>
        <description>
          How to leverage Blue Team tools to make your malware stealthier - 
          If you have ever checked the “Behavior” section on VirusTotal’s review of a sample, you have seen how it may flag suspicious activities performed by the executable you are analyzing. Irrespective of the number of detections that your sample gets...
        </description>
        <pubDate>Sun, 27 Oct 2024 00:00:00 -0400</pubDate>
        <link>https://rwxstoned.github.io/2024-10-27-CAPA-for-red-teams/</link>
        <guid isPermaLink="true">https://rwxstoned.github.io/2024-10-27-CAPA-for-red-teams/</guid>
      </item>
    
  </channel>
</rss>
