LocalStranger is a PoC for vulnerable “Microsoft Windows Hardware Compatibility Publisher” signed driver, demonstrated through a basic unsigned driver mapper and NT AUTHORITY escalation.
https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/
submitted by /u/noobesINC (https://www.reddit.com/user/noobesINC)
[link] (https://github.com/nbs32k/LocalStranger) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/)
https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/
submitted by /u/noobesINC (https://www.reddit.com/user/noobesINC)
[link] (https://github.com/nbs32k/LocalStranger) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/)
Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution (arXiv:2609.29808)
https://www.reddit.com/r/redteamsec/comments/1wqrjib/hard_stop_kernellevel_preemption_and_containment/
submitted by /u/wlvmtb (https://www.reddit.com/user/wlvmtb)
[link] (https://arxiv.org/abs/2609.29808) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqrjib/hard_stop_kernellevel_preemption_and_containment/)
https://www.reddit.com/r/redteamsec/comments/1wqrjib/hard_stop_kernellevel_preemption_and_containment/
submitted by /u/wlvmtb (https://www.reddit.com/user/wlvmtb)
[link] (https://arxiv.org/abs/2609.29808) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqrjib/hard_stop_kernellevel_preemption_and_containment/)
How to get a red team job? (pasted anything just to post, not sure if cant post this type of content, sorry lol)
https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/
<!-- SC_OFF -->Sup guys, lemme ask u something, ive been working as a web developer for 5 years, and in 2024 i started to learn cibersecurity, but due to work and other things that happened i lost the focus, so in the 2025 october i started back to practice and learn, studying at htb academy, tryhackme ive already done and learnt a lot, im doing portswigger labs(xss, sqli, idoor and etc), maldev(shellcode injection, process hollowing, dll side-loading, reflective dll, peb walking, api hashing, junk code), reverse engineering(have already done some crackmes to learn assembly), network(i study by myself cuz i like this subject a lot, test everything in my vps, firewall, docker, tcpdump, ssh tunelling to disguise traffic, macspoof to bypass switches configs, deauth to attack some networks), started to learn about slive c2(dns exfiltration, tcp exfiltration, icmp exfiltration) and etc. My point here is, i would like to hear from people that already work with it, what is the path to get there, cuz a lotta things a know and practice everyday, but theres things that i know that i need to study more like AD, OSINT, OPSEC. That said what would u guys recommend me to do to get there, cuz red team is my dream work And another thing, i feel lost cuz like, at web dev i can get a work easily even with ai, but in security as i dont have any experience how could a jr get a job lol, with all those ai's out there, and i think im a skid, but im not sure lmao thanks, know that u guys work what i ever wanted i my life <!-- SC_ON --> submitted by /u/Deex__ (https://www.reddit.com/user/Deex__)
[link] (https://www.youtube.com/watch?v=rHxYZwMz-DY&list=PLBf0hzazHTGMjSlPmJ73Cydh9vCqxukCu) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/)
https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/
<!-- SC_OFF -->Sup guys, lemme ask u something, ive been working as a web developer for 5 years, and in 2024 i started to learn cibersecurity, but due to work and other things that happened i lost the focus, so in the 2025 october i started back to practice and learn, studying at htb academy, tryhackme ive already done and learnt a lot, im doing portswigger labs(xss, sqli, idoor and etc), maldev(shellcode injection, process hollowing, dll side-loading, reflective dll, peb walking, api hashing, junk code), reverse engineering(have already done some crackmes to learn assembly), network(i study by myself cuz i like this subject a lot, test everything in my vps, firewall, docker, tcpdump, ssh tunelling to disguise traffic, macspoof to bypass switches configs, deauth to attack some networks), started to learn about slive c2(dns exfiltration, tcp exfiltration, icmp exfiltration) and etc. My point here is, i would like to hear from people that already work with it, what is the path to get there, cuz a lotta things a know and practice everyday, but theres things that i know that i need to study more like AD, OSINT, OPSEC. That said what would u guys recommend me to do to get there, cuz red team is my dream work And another thing, i feel lost cuz like, at web dev i can get a work easily even with ai, but in security as i dont have any experience how could a jr get a job lol, with all those ai's out there, and i think im a skid, but im not sure lmao thanks, know that u guys work what i ever wanted i my life <!-- SC_ON --> submitted by /u/Deex__ (https://www.reddit.com/user/Deex__)
[link] (https://www.youtube.com/watch?v=rHxYZwMz-DY&list=PLBf0hzazHTGMjSlPmJ73Cydh9vCqxukCu) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/)
Build guide for GOAD lab on Proxmox, Sliver C2, Redirectors and Operator behind pfSense.
https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/
<!-- SC_OFF -->Hi guys, this is my guide and the notes uploaded in github for the lab. I wanted to build this avoiding using Ludus and Wireguard, as I needed a more realistic approach and also to manage the network from pfSense. As the GOAD repo and the process build on Proxmox needed troubleshooting and some changes in the configuration files, decided to upload a guide and post here for anyone interested to create the lab. <!-- SC_ON --> submitted by /u/GMCobra (https://www.reddit.com/user/GMCobra)
[link] (https://github.com/pho5nix/Red-Team-GOAD-Lab-Proxmox) [comments] (https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/)
https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/
<!-- SC_OFF -->Hi guys, this is my guide and the notes uploaded in github for the lab. I wanted to build this avoiding using Ludus and Wireguard, as I needed a more realistic approach and also to manage the network from pfSense. As the GOAD repo and the process build on Proxmox needed troubleshooting and some changes in the configuration files, decided to upload a guide and post here for anyone interested to create the lab. <!-- SC_ON --> submitted by /u/GMCobra (https://www.reddit.com/user/GMCobra)
[link] (https://github.com/pho5nix/Red-Team-GOAD-Lab-Proxmox) [comments] (https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/)
Nvidia just announced their DPU-based Open Agent Safety Platform. Here is an architectural comparison against kernel-level eBPF containment.
https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/
<!-- SC_OFF -->Nvidia launched their Open Agent Safety Platform this morning, relying on an out-of-band DPU (Sentry on BlueField) to achieve what they call "millisecond-scale quarantine" for autonomous agents. For the red and blue teams looking at agent containment, the architectural contrast between their hardware approach and an in-line kernel approach is worth breaking down: The DPU Approach (Nvidia): Moving the enforcement layer physically out-of-band to a DPU is excellent for surviving a total host-kernel root compromise. However, it relies on telemetry crossing the PCIe bus to evaluate policy. In compute time, a millisecond is an eternity—more than enough time for a rogue agent to successfully exfiltrate a small payload or drop a beacon before the DPU drops the connection. The In-Line Kernel Approach (eBPF): In my recent preprint (Hard Stop, arXiv: 2609.29808), we tested an alternative software-only approach. By hooking security_bpf and security_file_open via eBPF LSM at the syscall boundary, you can achieve sub-5-microsecond preemption. Because it stays in-line, it intercepts and denies the action before the kernel processes it, achieving zero-leakage containment without the hardware round-trip. Nvidia’s platform is a massive step forward for enterprise zero-trust, but it requires proprietary silicon. If you rigorously enforce your unprivileged namespace and cgroup boundaries, kernel-level preemption gets you true zero-leakage isolation orders of magnitude faster on commodity Linux hardware. Curious to hear from the offensive side—if you were red-teaming an agent, would you rather race an out-of-band DPU or try to bypass an in-line eBPF LSM hook? (Paper link: https://arxiv.org/abs/2609.29808 / Code: https://github.com/joseluispino/hardstop) <!-- SC_ON --> submitted by /u/wlvmtb (https://www.reddit.com/user/wlvmtb)
[link] (https://nvidianews.nvidia.com/news/open-agent-safety-platform) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/)
https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/
<!-- SC_OFF -->Nvidia launched their Open Agent Safety Platform this morning, relying on an out-of-band DPU (Sentry on BlueField) to achieve what they call "millisecond-scale quarantine" for autonomous agents. For the red and blue teams looking at agent containment, the architectural contrast between their hardware approach and an in-line kernel approach is worth breaking down: The DPU Approach (Nvidia): Moving the enforcement layer physically out-of-band to a DPU is excellent for surviving a total host-kernel root compromise. However, it relies on telemetry crossing the PCIe bus to evaluate policy. In compute time, a millisecond is an eternity—more than enough time for a rogue agent to successfully exfiltrate a small payload or drop a beacon before the DPU drops the connection. The In-Line Kernel Approach (eBPF): In my recent preprint (Hard Stop, arXiv: 2609.29808), we tested an alternative software-only approach. By hooking security_bpf and security_file_open via eBPF LSM at the syscall boundary, you can achieve sub-5-microsecond preemption. Because it stays in-line, it intercepts and denies the action before the kernel processes it, achieving zero-leakage containment without the hardware round-trip. Nvidia’s platform is a massive step forward for enterprise zero-trust, but it requires proprietary silicon. If you rigorously enforce your unprivileged namespace and cgroup boundaries, kernel-level preemption gets you true zero-leakage isolation orders of magnitude faster on commodity Linux hardware. Curious to hear from the offensive side—if you were red-teaming an agent, would you rather race an out-of-band DPU or try to bypass an in-line eBPF LSM hook? (Paper link: https://arxiv.org/abs/2609.29808 / Code: https://github.com/joseluispino/hardstop) <!-- SC_ON --> submitted by /u/wlvmtb (https://www.reddit.com/user/wlvmtb)
[link] (https://nvidianews.nvidia.com/news/open-agent-safety-platform) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/)
WINDOWS PRIVILEGE ESCALATION USING NCSI ACTIVE PROBES
https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/
<!-- SC_OFF -->Peter Gabaldon from LABS @ ITRES discusess a vulnerability in the Windows Network Connectivity Status Indicator (NCSI) that can be exploited to escalate privileges from a low-privileged user to local admin. The attack leverages proxy configuration flaws to relay authentication to an Active Directory Certificate Services endpoint, enabling attackers to forge access tickets. <!-- SC_ON --> submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/)
https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/
<!-- SC_OFF -->Peter Gabaldon from LABS @ ITRES discusess a vulnerability in the Windows Network Connectivity Status Indicator (NCSI) that can be exploited to escalate privileges from a low-privileged user to local admin. The attack leverages proxy configuration flaws to relay authentication to an Active Directory Certificate Services endpoint, enabling attackers to forge access tickets. <!-- SC_ON --> submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/)
Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and evaluation scripts.
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5
https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5
I still have the screenshot.Continue reading on Medium » (https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5)
Smali By bithowl: Chapter 13 Object Operations
https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5
https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium » (https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5)
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
I still have the screenshot.Continue reading on Medium »
Read more...
I still have the screenshot.Continue reading on Medium »
Read more...
Medium
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
I still have the screenshot.
Smali By bithowl: Chapter 13 Object Operations
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium »
Read more...
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium »
Read more...
Medium
Smali By bithowl: Chapter 13 Object Operations
“The Register Has an Object. But What Exactly Is It?”