#OpSec
#Red_Team_Tactics
1⃣. Initial Access. The Art of Getting In
0xdbgman.github.io/posts/ini…
// Payload Development (DLL Sideloading, Shellcode Loaders, Syscalls), HTML Smuggling, Phishing (QR Code Quishing, Teams Phishing), AitM/MFA Bypass (Evilginx, Device Code Phishing), Psw Spraying, Exploiting Public-Facing Apps, Vishing, Physical Access (Rubber Ducky, Bash Bunny), Supply Chain attacks with real-world APT case studies
2⃣. Red Team Infrastructure. The Full Picture: From Domain to Beacon
0xdbgman.github.io/posts/red…
// C2 Frameworks, Redirectors, CDN Relays (Azure, AWS, GCP), Serverless Lambda, Cloudflare Tunnels, Phishing Infrastructure, Mail Servers, Malleable Profiles, and full OPSEC hardening
3⃣. Persistence: The Art of Staying In
0xdbgman.github.io/posts/per…
// 50 techniques across Windows, Scheduled Tasks, WMI, Services, DLL/COM/AppDomainManager, UEFI Bootkits, Active Directory, Linux, macOS, and Cloud (Azure/AWS/GCP, Kubernetes)