#OpSec
#Red_Team_Tactics
1โฃ. Initial Access. The Art of Getting In
0xdbgman.github.io/posts/iniโฆ
// Payload Development (DLL Sideloading, Shellcode Loaders, Syscalls), HTML Smuggling, Phishing (QR Code Quishing, Teams Phishing), AitM/MFA Bypass (Evilginx, Device Code Phishing), Psw Spraying, Exploiting Public-Facing Apps, Vishing, Physical Access (Rubber Ducky, Bash Bunny), Supply Chain attacks with real-world APT case studies
2โฃ. Red Team Infrastructure. The Full Picture: From Domain to Beacon
0xdbgman.github.io/posts/redโฆ
// C2 Frameworks, Redirectors, CDN Relays (Azure, AWS, GCP), Serverless Lambda, Cloudflare Tunnels, Phishing Infrastructure, Mail Servers, Malleable Profiles, and full OPSEC hardening
3โฃ. Persistence: The Art of Staying In
0xdbgman.github.io/posts/perโฆ
// 50 techniques across Windows, Scheduled Tasks, WMI, Services, DLL/COM/AppDomainManager, UEFI Bootkits, Active Directory, Linux, macOS, and Cloud (Azure/AWS/GCP, Kubernetes)