MacroPack new version is out! 🥳
With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario!
Also now everything can be leveraged with the new BallisKit GUI! 😎
#redteam
Introducing EDR Eclipse, our new premium extension for ShellcodePack!
EDR Eclipse is an advanced kernel-assisted telemetry suppression module designed to blind the EDR without terminating it.
Key capabilities:
• Kernel callback removal
• Dynamic offset resolution
• Telemetry suppression
• ETW-TI suppression
• Minifilter neutralization
Due to the sensitive nature of the technology, availability will be limited to eligible customers.
More technical details, demonstrations, and videos are available on the BallisKit Discord!
#RedTeam
New DarwinOps release! We mainly added more EDR Evasion profiles and improved JXA escape with the ability to generate a Macho/Dylib that does not use Osascript (or OSAKit) . This prevents detection of any Osascript EST events!
#redteam
We updated our Sliver C2 BallisKit tutorial to adapt to the latest Sliver version.
Learn how to use ShellcodePack/MacroPack to harden Sliver implants and turn them into initial access payloads!
More C2 tutorials available on the blog (Adaptix, Mythic)
blog.balliskit.com/tutorial-…
LNK is still a top-tier initial access vector. Most defenses still underestimate it.
Soon to be released MacroPack 2.8.9 pushes LNK tradecraft further:
• Advanced customization & evasion workarounds
• Improved EDR bypass
• Several delivery alternatives
Version also contains other features such as VHDX container, new .NET shellcode injection, etc.
Built from real-world testing against modern EDRs.
#RedTeam
I just wrote a tutorial explaining how to combine Adaptix C2 with MacroPack and ShellcodePack! This provides multiple initial access and EDR evasion options to Adaptix C2 users.
Tutorial includes: LNK, CLickOnce, DLL Sideloading, Exe, HTA, etc!
#redteamblog.balliskit.com/tutorial-…
The next ShellcodePack version supports AppDomain injection payloads! We also simplified and improved DLL sideloading/proxying and updated the EDR bypass profiles.
Sideload anything with a few clicks! 😎
#redteam
Using #darwinOps, after setting up your redteam scenario, you can choose which phishing template will be most convincing for your engagement 😎
Contact us to know more about redteaming on macOS and ready to use phishing templates!
#redteam
MacroPack new version is out! 🥳
With improved EDR evasion profiles and all kind of ready to use initial access formats and scenario!
Also now everything can be leveraged with the new BallisKit GUI! 😎
#redteam
**OFFICIAL** EDR Tier List for 2026! Based on nothing but the people in chat, vibes, guests, opinions and limited experience. Thanks to @EmericNasi@ShitSecure@_JohnHammond and @domchell for jumping in a guests to help me out this time around!
👋Starting 2026 by updating my EDR tier list 🥳Going live on Twitch/YouTube Sunday at 20:00 CEST! Counting on you all to be there for some fun banter 🤡
Aslo AI gave me chad jaw line 😂