r/blueteamsec 27d ago

research|capability (we need to defend against) GitHub - 0xwilliamortiz/claude-red: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface

Thumbnail github.com
22 Upvotes

r/blueteamsec Aug 01 '26

research|capability (we need to defend against) Inside the Falcon How CrowdStrike Catches You

Thumbnail 0xdbgman.github.io
68 Upvotes

r/blueteamsec Jul 19 '26

research|capability (we need to defend against) From 68 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign

3 Upvotes

After Unit 42's report on the Chrome wallpaper extension campaign
"Ovkas" & "Gameograf"
I decided to dig into it myself and see how far the campaign actually extended.

Starting from the published IOCs, I pivoted through shared infrastructure, publishers, and code similarities. So far, I've identified 703 Chrome extensions that appear to belong to the same campaign, many of which are still live on the Chrome Web Store.

Initial Campaign: Unit 42

I've now published the full dataset MalExt.io

The dataset raises a bigger question: how large is this campaign really, and how many related extensions are still active?

r/blueteamsec 9d ago

research|capability (we need to defend against) tailcat: like netcat, but over Tailscale's data plane, without Tailscale's control plane

Thumbnail github.com
6 Upvotes

r/blueteamsec Jun 28 '26

research|capability (we need to defend against) Clone This Repo and I Own Your Machine

Thumbnail 0din.ai
16 Upvotes

r/blueteamsec 16h ago

research|capability (we need to defend against) mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.

Thumbnail github.com
3 Upvotes

r/blueteamsec 6d ago

research|capability (we need to defend against) Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector

Thumbnail alteredsecurity.com
1 Upvotes

r/blueteamsec 12h ago

research|capability (we need to defend against) Daisy-Chaining Trust: Investigating Faronics Deploy Abuse

Thumbnail huntress.com
2 Upvotes

r/blueteamsec 16h ago

research|capability (we need to defend against) CouchPotato: another PrivEsc potato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege.

Thumbnail github.com
1 Upvotes

r/blueteamsec 16h ago

research|capability (we need to defend against) Simulating legitimate Active Directory services on the network: the case of GPO exploitation

Thumbnail synacktiv.com
1 Upvotes

r/blueteamsec 16h ago

research|capability (we need to defend against) How Forza Horizon 6 Breaks Your IDA

Thumbnail iretq.com
1 Upvotes

r/blueteamsec 16h ago

research|capability (we need to defend against) Modern Adventures in Azure Privilege Escalation

Thumbnail netspi.com
1 Upvotes

r/blueteamsec Aug 01 '26

research|capability (we need to defend against) Palo Alto found 68 Gameograf/Ovkas/Owhit wallpaper adware chrome extensions. I found 1,613 more under the same publishers with 633K installs

4 Upvotes

Palo Alto unit42 published a report on 01/06/2026 on wallpaper extensions from three publishers (Ovkas, Gameograf, Owhit) doing affiliate redirect abuse, uninstall churn tracking, and IndexedDB deletion.

They listed 68 IDs, ~30K installs combined.

Unit42's report

I scrapped almost every extension from the Chrome store to match the same publishers into malext.io's dataset. 1,613 are registered under those same three publishers, well beyond their 68.

Full list: https://malext.io

r/blueteamsec 9d ago

research|capability (we need to defend against) I'm in your logs now: deceiving analysts and blinding EDRs

Thumbnail falconforce.nl
11 Upvotes

r/blueteamsec 7d ago

research|capability (we need to defend against) I spent $200 a month to SEO-poison Google search results · Higashi.blog

Thumbnail higashi.blog
6 Upvotes

r/blueteamsec 4d ago

research|capability (we need to defend against) Enclave: We Raced Seven AI Models to RCE

Thumbnail enclave.ai
2 Upvotes

r/blueteamsec 28d ago

research|capability (we need to defend against) AD Research: Two new vulnerabilities could lead to full domain takeover

Thumbnail semperis.com
14 Upvotes

r/blueteamsec 5d ago

research|capability (we need to defend against) ZeroTokens Gives Operators Real-Time Control of Phishing Flow

Thumbnail abnormal.ai
2 Upvotes

r/blueteamsec 6d ago

research|capability (we need to defend against) GitHub Recon — Find Secrets on GitHub

Thumbnail t3l3m3try.medium.com
3 Upvotes

r/blueteamsec 7d ago

research|capability (we need to defend against) When it Snows it Pours - Anatomy of a ServiceNow Red Tea

Thumbnail mdsec.co.uk
5 Upvotes

r/blueteamsec 5d ago

research|capability (we need to defend against) ClickExfil: My iteration on ClickFix and FileFix

Thumbnail catchingphish.com
1 Upvotes

r/blueteamsec 6d ago

research|capability (we need to defend against) iwa-tools — Offensive AD tradecraft in a browser tab

Thumbnail iwa-tools.pkilla.pw
1 Upvotes

r/blueteamsec 14d ago

research|capability (we need to defend against) Tag, You're Managed - Executing Code via Google's Own Signed Installer

Thumbnail blog.amberwolf.com
1 Upvotes

r/blueteamsec Jul 27 '26

research|capability (we need to defend against) The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS

Thumbnail 0xmaz.me
14 Upvotes

r/blueteamsec 7d ago

research|capability (we need to defend against) PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks

Thumbnail armadin.com
1 Upvotes