BEAR-C2 V2.0 — A C2 Framework for Realistic Adversary Simulation
https://www.reddit.com/r/redteamsec/comments/1wg0nsr/bearc2_v20_a_c2_framework_for_realistic_adversary/
<!-- SC_OFF -->I built BEAR-C2 around one simple idea Instead of rebuilding a C2 from scratch every time I want to simulate a different threat actor, I wanted a framework that could adapt to different adversary scenarios and TTPs The main goal is to support realistic adversary simulations based on real-world campaigns and threat intelligence, including operations associated with threat actors and APT groups from Russia, China, Iran and North Korea With BEAR-C2 V2.0, the focus is on flexibility and switching between different protocols, C2 channels, encryption methods, OPSEC techniques, proxies and exfiltration profiles, so the same framework can be adapted to different simulation scenarios The project started as a much simpler idea and evolved through different adversary simulation projects and security research This is where BEAR-C2 V2.0 is today, and I’m still working on it. <!-- SC_ON --> submitted by /u/S3N4T0R-0X0 (https://www.reddit.com/user/S3N4T0R-0X0)
[link] (https://github.com/S3N4T0R-0X0/BEAR-C2) [comments] (https://www.reddit.com/r/redteamsec/comments/1wg0nsr/bearc2_v20_a_c2_framework_for_realistic_adversary/)
https://www.reddit.com/r/redteamsec/comments/1wg0nsr/bearc2_v20_a_c2_framework_for_realistic_adversary/
<!-- SC_OFF -->I built BEAR-C2 around one simple idea Instead of rebuilding a C2 from scratch every time I want to simulate a different threat actor, I wanted a framework that could adapt to different adversary scenarios and TTPs The main goal is to support realistic adversary simulations based on real-world campaigns and threat intelligence, including operations associated with threat actors and APT groups from Russia, China, Iran and North Korea With BEAR-C2 V2.0, the focus is on flexibility and switching between different protocols, C2 channels, encryption methods, OPSEC techniques, proxies and exfiltration profiles, so the same framework can be adapted to different simulation scenarios The project started as a much simpler idea and evolved through different adversary simulation projects and security research This is where BEAR-C2 V2.0 is today, and I’m still working on it. <!-- SC_ON --> submitted by /u/S3N4T0R-0X0 (https://www.reddit.com/user/S3N4T0R-0X0)
[link] (https://github.com/S3N4T0R-0X0/BEAR-C2) [comments] (https://www.reddit.com/r/redteamsec/comments/1wg0nsr/bearc2_v20_a_c2_framework_for_realistic_adversary/)
numa v0.23.1
Portable DNS resolver with ad blocking, local .numa domains, developer overrides, and ODoH privacy. Supports recursive resolution, DNSSEC, DoT/DoH listeners, and LAN service discovery in a single binary.
Read more...
Portable DNS resolver with ad blocking, local .numa domains, developer overrides, and ODoH privacy. Supports recursive resolution, DNSSEC, DoT/DoH listeners, and LAN service discovery in a single binary.
Read more...
envocabulary v1.0.5
Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across zsh and bash on macOS, Linux, and FreeBSD.
Read more...
Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across zsh and bash on macOS, Linux, and FreeBSD.
Read more...
Osintgram v2.0
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
Read more...
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
Read more...
70% of Hunters Use AI to Find Bugs. The $15,000 Payouts Come from Hunting the AI.
30-Second Version: 70% of HackerOne researchers now use AI tools in their workflow; Bugcrowd puts hacker-side adoption at 82%.Continue reading on MeetCyber »
Read more...
30-Second Version: 70% of HackerOne researchers now use AI tools in their workflow; Bugcrowd puts hacker-side adoption at 82%.Continue reading on MeetCyber »
Read more...
Medium
70% of Hunters Use AI to Find Bugs. The $15,000 Payouts Come from Hunting the AI.
30-Second Version: 70% of HackerOne researchers now use AI tools in their workflow; Bugcrowd puts hacker-side adoption at 82%. Both numbers…
From Web to AI Security: What I achieved Red Teaming LLMs for the past 4 Months
First of all it has been six months since I last posted a blog, sorry for the inconsistency. But a lot has changed in the past 4 months of…Continue reading on Medium »
Read more...
First of all it has been six months since I last posted a blog, sorry for the inconsistency. But a lot has changed in the past 4 months of…Continue reading on Medium »
Read more...
Medium
From Web to AI Security: What I achieved Red Teaming LLMs for the past 4 Months
First of all it has been six months since I last posted a blog, sorry for the inconsistency. But a lot has changed in the past 4 months of…
STIX & TAXII Explained: A Step-by-Step Guide to Cyber Threat Intelligence
STIX & TAXII ExplainedContinue reading on Medium »
Read more...
STIX & TAXII ExplainedContinue reading on Medium »
Read more...
Medium
STIX & TAXII Explained: A Step-by-Step Guide to Cyber Threat Intelligence
STIX & TAXII Explained
suricata suricata-8.0.7
Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat hunting.
Read more...
Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat hunting.
Read more...
Where Are the Robots — picoCTF Write-up | Finding Hidden Pages with robots.txt
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Where Are the Robots — picoCTF Write-up | Finding Hidden Pages with robots.txt
Introduction
nuclei-burp-plugin v1.1.4
https://kitploit.com/en/posts/github-projectdiscovery-nuclei-burp-plugin-v114
https://kitploit.com/en/posts/github-projectdiscovery-nuclei-burp-plugin-v114
Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and syntax highlighting.
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.