GitHub - IceCubeSandwich/CaddySmith: Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.
https://www.reddit.com/r/redteamsec/comments/1uttc87/github_icecubesandwichcaddysmith_generate_caddy/
<!-- SC_OFF -->Saw a tool like this for Apache a while back but I prefer Caddy, so I built CaddySmith (name pending kinda). Why Caddy? Single binary, automatic Let's Encrypt, cleaner config. Point it at a profile and it generates a Caddyfile that proxies beacon traffic to your teamserver and everything else arrives at a decoy. Strict mode enforces UA and all client headers from the profile. Sliver support is there too since the format is just JSON. --smoke generates a few curl commands to validate the redirector post-deploy. Test it out and tell me what you think. <!-- SC_ON --> submitted by /u/Kind_Giraffe_3279 (https://www.reddit.com/user/Kind_Giraffe_3279)
[link] (https://github.com/IceCubeSandwich/CaddySmith) [comments] (https://www.reddit.com/r/redteamsec/comments/1uttc87/github_icecubesandwichcaddysmith_generate_caddy/)
https://www.reddit.com/r/redteamsec/comments/1uttc87/github_icecubesandwichcaddysmith_generate_caddy/
<!-- SC_OFF -->Saw a tool like this for Apache a while back but I prefer Caddy, so I built CaddySmith (name pending kinda). Why Caddy? Single binary, automatic Let's Encrypt, cleaner config. Point it at a profile and it generates a Caddyfile that proxies beacon traffic to your teamserver and everything else arrives at a decoy. Strict mode enforces UA and all client headers from the profile. Sliver support is there too since the format is just JSON. --smoke generates a few curl commands to validate the redirector post-deploy. Test it out and tell me what you think. <!-- SC_ON --> submitted by /u/Kind_Giraffe_3279 (https://www.reddit.com/user/Kind_Giraffe_3279)
[link] (https://github.com/IceCubeSandwich/CaddySmith) [comments] (https://www.reddit.com/r/redteamsec/comments/1uttc87/github_icecubesandwichcaddysmith_generate_caddy/)
AntiVE-BehaviorWatch ( AI model Inside a EXE )
https://www.reddit.com/r/redteamsec/comments/1uug7hr/antivebehaviorwatch_ai_model_inside_a_exe/
submitted by /u/ObligationLucky842 (https://www.reddit.com/user/ObligationLucky842)
[link] (https://github.com/NirvanaOn/AntiVE-BehaviorWatch) [comments] (https://www.reddit.com/r/redteamsec/comments/1uug7hr/antivebehaviorwatch_ai_model_inside_a_exe/)
https://www.reddit.com/r/redteamsec/comments/1uug7hr/antivebehaviorwatch_ai_model_inside_a_exe/
submitted by /u/ObligationLucky842 (https://www.reddit.com/user/ObligationLucky842)
[link] (https://github.com/NirvanaOn/AntiVE-BehaviorWatch) [comments] (https://www.reddit.com/r/redteamsec/comments/1uug7hr/antivebehaviorwatch_ai_model_inside_a_exe/)
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
https://www.reddit.com/r/redteamsec/comments/1uv51jv/persistence_via_fake_amsi_provider_playbook/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2026/07/13/amsi-provider/) [comments] (https://www.reddit.com/r/redteamsec/comments/1uv51jv/persistence_via_fake_amsi_provider_playbook/)
https://www.reddit.com/r/redteamsec/comments/1uv51jv/persistence_via_fake_amsi_provider_playbook/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2026/07/13/amsi-provider/) [comments] (https://www.reddit.com/r/redteamsec/comments/1uv51jv/persistence_via_fake_amsi_provider_playbook/)
What separates a real red-team lab from a tool-running lab?
https://www.reddit.com/r/redteamsec/comments/1uva5qt/what_separates_a_real_redteam_lab_from_a/
<!-- SC_OFF -->Running tools is easy. Building an operation that survives detection is the real skill. A realistic red-team lab should include: Infrastructure and C2 setup OPSEC and payload delivery Credential access and privilege escalation Lateral movement and persistence Detection-aware execution Reporting and remediation context What is the most important element that most red-team labs still miss? Redfox Blog:
https://www.redfoxsec.com/blog/adversary-simulation-vs-penetration-testing-which-does-your-business-need <!-- SC_ON --> submitted by /u/redfoxsecurity (https://www.reddit.com/user/redfoxsecurity)
[link] (https://www.redfoxsec.com/blog/adversary-simulation-vs-penetration-testing-which-does-your-business-need) [comments] (https://www.reddit.com/r/redteamsec/comments/1uva5qt/what_separates_a_real_redteam_lab_from_a/)
https://www.reddit.com/r/redteamsec/comments/1uva5qt/what_separates_a_real_redteam_lab_from_a/
<!-- SC_OFF -->Running tools is easy. Building an operation that survives detection is the real skill. A realistic red-team lab should include: Infrastructure and C2 setup OPSEC and payload delivery Credential access and privilege escalation Lateral movement and persistence Detection-aware execution Reporting and remediation context What is the most important element that most red-team labs still miss? Redfox Blog:
https://www.redfoxsec.com/blog/adversary-simulation-vs-penetration-testing-which-does-your-business-need <!-- SC_ON --> submitted by /u/redfoxsecurity (https://www.reddit.com/user/redfoxsecurity)
[link] (https://www.redfoxsec.com/blog/adversary-simulation-vs-penetration-testing-which-does-your-business-need) [comments] (https://www.reddit.com/r/redteamsec/comments/1uva5qt/what_separates_a_real_redteam_lab_from_a/)
Python Web Penetration Testing
https://python.plainenglish.io/python-web-penetration-testing-c0d127b69c2f?source=rss------bug_bounty-5
https://python.plainenglish.io/python-web-penetration-testing-c0d127b69c2f?source=rss------bug_bounty-5
Day 2: The Heart of HTTP — Interacting with Web Applications Like a ProContinue reading on Python in Plain English » (https://python.plainenglish.io/python-web-penetration-testing-c0d127b69c2f?source=rss------bug_bounty-5)
UMANG App Vulnerability: Why Responsible Disclosure Matters More Than Headlines
https://medium.com/@radhavidhale4/umang-app-vulnerability-why-responsible-disclosure-matters-more-than-headlines-51a87c4fa4f7?source=rss------bug_bounty-5
n recent days, reports have emerged regarding a security vulnerability in the UMANG (Unified Mobile Application for New-age Governance)…Continue reading on Medium » (https://medium.com/@radhavidhale4/umang-app-vulnerability-why-responsible-disclosure-matters-more-than-headlines-51a87c4fa4f7?source=rss------bug_bounty-5)
https://medium.com/@radhavidhale4/umang-app-vulnerability-why-responsible-disclosure-matters-more-than-headlines-51a87c4fa4f7?source=rss------bug_bounty-5
n recent days, reports have emerged regarding a security vulnerability in the UMANG (Unified Mobile Application for New-age Governance)…Continue reading on Medium » (https://medium.com/@radhavidhale4/umang-app-vulnerability-why-responsible-disclosure-matters-more-than-headlines-51a87c4fa4f7?source=rss------bug_bounty-5)
How Automatic Link Generation in Transactional Emails Can Introduce Security Risks
https://medium.com/@GERRR4Y/how-automatic-link-generation-in-transactional-emails-can-introduce-security-risks-d83f6b7d54aa?source=rss------bug_bounty-5
https://medium.com/@GERRR4Y/how-automatic-link-generation-in-transactional-emails-can-introduce-security-risks-d83f6b7d54aa?source=rss------bug_bounty-5
بسم الله والصلاة والسلام على رسول الله الحمد لله الذي علم بالقلم علم الإنسان ما لم يعلم والصلاة والسلام على خير معلم الناس الخير محمدContinue reading on Medium » (https://medium.com/@GERRR4Y/how-automatic-link-generation-in-transactional-emails-can-introduce-security-risks-d83f6b7d54aa?source=rss------bug_bounty-5)
I Just Wanted a Cold Coffee. Instead I Found a Master Key to a Vending Machine Empire.
https://medium.com/@gokul965/i-just-wanted-a-cold-coffee-instead-i-found-a-master-key-to-a-vending-machine-empire-fc4bad7bc1db?source=rss------bug_bounty-5
https://medium.com/@gokul965/i-just-wanted-a-cold-coffee-instead-i-found-a-master-key-to-a-vending-machine-empire-fc4bad7bc1db?source=rss------bug_bounty-5
A cautionary tale about snacks, curiosity, and why you should never F12 near a vending machine.Continue reading on Medium » (https://medium.com/@gokul965/i-just-wanted-a-cold-coffee-instead-i-found-a-master-key-to-a-vending-machine-empire-fc4bad7bc1db?source=rss------bug_bounty-5)
The Endpoint Everyone Ignored Just Took Down a Server
A $1,024 bug hidden inside the most ignored endpoint on the platform — and the mistake every developer makes without knowing it.Continue reading on Medium »
Read more...
A $1,024 bug hidden inside the most ignored endpoint on the platform — and the mistake every developer makes without knowing it.Continue reading on Medium »
Read more...
Medium
The Endpoint Everyone Ignored Just Took Down a Server
A $1,024 bug hidden inside the most ignored endpoint on the platform — and the mistake every developer makes without knowing it.
The Endpoint Everyone Ignored Just Took Down a Server
https://medium.com/@Aacle/the-endpoint-everyone-ignored-just-took-down-a-server-c32d51cf886e?source=rss------bug_bounty-5
https://medium.com/@Aacle/the-endpoint-everyone-ignored-just-took-down-a-server-c32d51cf886e?source=rss------bug_bounty-5
A $1,024 bug hidden inside the most ignored endpoint on the platform — and the mistake every developer makes without knowing it.Continue reading on Medium » (https://medium.com/@Aacle/the-endpoint-everyone-ignored-just-took-down-a-server-c32d51cf886e?source=rss------bug_bounty-5)
How a Simple S3 Bucket Misconfiguration Turned into a Security Assessment
“Every bug hunter dreams of finding that one small clue that leads to something much bigger.”Continue reading on Medium »
Read more...
“Every bug hunter dreams of finding that one small clue that leads to something much bigger.”Continue reading on Medium »
Read more...
Medium
How a Simple S3 Bucket Misconfiguration Turned into a Security Assessment
“Every bug hunter dreams of finding that one small clue that leads to something much bigger.”
10 Recon Techniques Every Pentester Should Master in 2026
The reconnaissance methods that help security professionals map attack surfaces before a single exploit is launched.Continue reading on InfoSec-Writes Up »
Read more...
The reconnaissance methods that help security professionals map attack surfaces before a single exploit is launched.Continue reading on InfoSec-Writes Up »
Read more...
Medium
10 Recon Techniques Every Pentester Should Master in 2026
The reconnaissance methods that help security professionals map attack surfaces before a single exploit is launched.
How a Simple S3 Bucket Misconfiguration Turned into a Security Assessment
https://medium.com/@sunny561/how-a-simple-s3-bucket-misconfiguration-turned-into-a-security-assessment-6b4ac536652c?source=rss------bug_bounty-5
https://medium.com/@sunny561/how-a-simple-s3-bucket-misconfiguration-turned-into-a-security-assessment-6b4ac536652c?source=rss------bug_bounty-5