AI-Powered Red Teaming with SpecterInsight

T1059.001 PowerShell  Â·  T1027 Obfuscation  Â·  T1547.001 Run Keys  Â·  T1053.005 Scheduled Tasks  Â·  T1003.002 SAM Dump  Â·  T1562.001 Disable Security Tools  Â·  T1046 Network Discovery  Â·  T1018 Remote System Discovery  Â·  T1134 Access Token Manipulation  Â·  T1021.003 WMI Lateral Movement  Â·  T1552.001 Credentials in Registry  Â·  T1082 System Information Discovery Feature Spotlight August 30,

AI-Powered Red Teaming with SpecterInsight Read More »

How to Build Threat Emulation Workflows

Operator Guide  Â·  SpecterInsight v7.0.0  Â·  Threat Emulation THREAT EMULATION WORKFLOWS SpecterInsight workflows let you encode an entire attack chain and run it repeatedly against a lab or authorized environment. In this guide, I’ll build one from initial access through lateral movement and show how I use each phase to check what the endpoint, network

How to Build Threat Emulation Workflows Read More »

Emulating APT28 PRISMEX with SpecterInsight

TLP:AMBER · For authorized operational and training use only SpecterInsight v7.0.0 Adversary Emulation  Â·  APT28 / Pawn Storm  Â·  2022–2025 PRISMEX Full kill chain emulation of Pawn Storm / APT28: from spear-phishing delivery through credential harvesting, WMI lateral movement, and a destructive user-profile wiper. Executed as a 33-cell SpecterInsight Workflow. Threat Actor APT28 / Pawn

Emulating APT28 PRISMEX with SpecterInsight Read More »

Feature Spotlight: The Zig Payload Pipelines

SpecterInsight’s Zig payload pipelines give you full cross-platform, native payload generation from a single server. Zig 0.16.0 is bundled as the compiler. It runs identically on Windows and Linux hosts and cross-compiles to any combination of OS (Windows, Linux, macOS) and architecture (x86, x86_64, aarch64) without any additional toolchain setup. Before the compiler sees a

Feature Spotlight: The Zig Payload Pipelines Read More »

Dumping LSASS Without Touching Disk: Improvements to ShadowDumper

While integrating LSASS dumping techniques into SpecterInsight’s dumper module, I used Offensive-Panda’s ShadowDumper as a reference point. That tool is great collection of LSASS dump techniques, but I also wanted to improve upon their research by addressing some of the issues that might result in detection by an EDR: The rest of this post walks

Dumping LSASS Without Touching Disk: Improvements to ShadowDumper Read More »

Profiling User Activity with EventLogs

Introduction Understanding user logon behavior is a powerful tool in red teaming and adversary simulations. By analyzing who logs into a system, when, from where, and how frequently, operators gain deep situational awareness that can inform stealthy movements, impersonation opportunities, and identify high-value targets. This post presents a PowerShell script built to extract and analyze

Profiling User Activity with EventLogs Read More »

Bypassing AMSI and Evading AV Detection with SpecterInsight

Introduction A few weeks ago, there was a post on reddit asking for advice on how to get their AMSI bypass through Windows Defender without being detected. Recently, it has become much more difficult to build payloads that can evade detection. Microsoft has out a ton of effort into deploying good heuristic signatures to block

Bypassing AMSI and Evading AV Detection with SpecterInsight Read More »

Building a RuntimeInstaller Payload Pipeline to Evade AV Detection

Overview In this post, we will build an automated pipeline for generating a .NET loader payload that can evade both AV detection and application controls. The tools used in this post are: What is a Payload Pipeline A payload pipeline is an automated process for generating red team payloads that can evade detection by antivirus,

Building a RuntimeInstaller Payload Pipeline to Evade AV Detection Read More »

Scroll to Top