GitHub - ofasgard/LibCPLTest: A shared library for Crystal Palace that allows you to unit test your PICOs.
A shared library for Crystal Palace that allows you to unit test your PICOs. - ofasgard/LibCPLTest
LibCPLTest: A shared library for Crystal Palace that allows you to unit test your PICOs. It's nothing too fancy, just a few helper functions and a macro, but it's helped me to create a consistent framework for testing my PIC capabilities.
github.com/ofasgard/Lib...
21.10.2025 16:06 โ ๐ 2 ๐ 3 ๐ฌ 0 ๐ 0
Yeah, it would be awesome to do a kind of semi-automated controlled detonation like that! So cool for purple teaming.
20.10.2025 16:19 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
A screenshot that showcases a PICO being unit tested. One of the test displays a failing assertion.
Anyway, simple little shared library for Crystal Palace to unit test your PICOs - coming soon!
20.10.2025 16:15 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
There are two wolves inside of me. One is a grotty little hacker that wants to make stuff that barely works, and the other is a software dev who wants to do โจTest Driven Developmentโจ
20.10.2025 16:14 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0
For example! I want a way to generate adozen almost-identical implants that all use slightly different tradecraft to achieve their goals, then run them all against a VM snapshot with an EDR agent installed and see which ones generate detections and why.
20.10.2025 08:56 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
I don't think the ecosystem is quite there yet, but I feel like we're so close to being able to perform fully automated fuzzing of modular tradecraft vs. EDR detections using Crystal Palace...
20.10.2025 08:55 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
a man with glasses looks at a plant in a can that says pepsi on it
ALT: a man with glasses looks at a plant in a can that says pepsi on it
I want to point out a few things happening with this fledgling Tradecraft Garden ecosystem. Right now things. But, how I see them in context of the overall model this could become.
17.10.2025 15:00 โ ๐ 5 ๐ 3 ๐ฌ 1 ๐ 1
A screenshot demonstrating the use of LibTP to proxy calls to NtAllocateVirtualMemory() while invoking a PICO.
Just got a chance to try it out, works like a charm!
17.10.2025 14:24 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
This is super cool! I'm guessing it'll only work on x64 due to the assembly used for the callback, right?
16.10.2025 16:44 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
And it's released! ๐
github.com/ofasgard/exe...
I've tested it with Rubeus and Seatbelt and a variety of different arguments, and it seems to be pretty stable as far as I can tell. If anyone uses this PICO and encounters bugs or instability, please let me know!
16.10.2025 16:13 โ ๐ 4 ๐ 3 ๐ฌ 0 ๐ 0
A screenshot of a Crystal Palace PICO running. It's invoking a .NET assembly, specifically Rubeus.
Working on a new PICO! This one is an in-memory CLR hoster that uses the same technique as execute-assembly/donut to invoke a .NET assembly without touching the disk.
16.10.2025 08:54 โ ๐ 5 ๐ 1 ๐ฌ 2 ๐ 1
The new Crystal Palace version is very cool.
Having DFR in your PIC code and just providing a resolver function is so much more ergonomic than having two different mechanisms for resolving APIs! I love it - already updated my HWB PICO to incorporate the new functionality.
14.10.2025 12:06 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0
CHATGPT: I understand where you're coming from. You worked really hard to get here, and now it's time to enjoy the fruit of your labors.
ISILDUR: So I should keep it? Elrond says I shouldn't
CHATGPT: The ring is precious. Sometimes friends don't have your best interests at heart.
ISILDUR: true
06.10.2025 13:58 โ ๐ 10586 ๐ 2996 ๐ฌ 41 ๐ 40
GitHub - ofasgard/hardware-breakpoint-pico: A PICO for Crystal Palace that implements hardware breakpoint hooking.
A PICO for Crystal Palace that implements hardware breakpoint hooking. - ofasgard/hardware-breakpoint-pico
I've been obsessed with @raphaelmudge.bsky.social 's Crystal Palace since I learned about it at Beacon earlier this month, so... here's a WIP PICO I wrote to hook functions with hardware breakpoints ๐
github.com/ofasgard/har...
29.09.2025 16:29 โ ๐ 6 ๐ 1 ๐ฌ 0 ๐ 0
I'm no expert, I've just had a lot of practice.
Red Team Lead.
My SE101 blog is not abandoned, just not had much time https://blog.ghostie.org/
Used to be Ghostie_ on the other place.
Off Air TV Archivist. Autistic. (They/Them)
I demand excellence in design & function & will not compromise.
https://archive.org/details/flemishdog linktr.ee/flemishdog
[ 'cto @sensepost.com', '@orangecyberdef', 'caffeine fueled', '(โฏยฐโกยฐ)โฏ๏ธต โปโโป', 'security guy', 'metalhead', 'i saw your password', 'KOOBo+KXleKAv+KXlSnjgaM=' ]
host of Cool People Who Did Cool Stuff. Co-owner of Strangers in a Tangled Wilderness. Latest book is The Immortal Choir Holds Every Voice. she/they
Cybertiger. Senior Staff technologist at @eff.org Fellow @citizenlab.ca Board member @openarchive.bsky.social. "Noted activist security type." The Register once called me a boffin. Anti-fascist. he/him. My skeets do not represent views of my employers โตฃ๐ด
๐ฆ Rust + Security ๐
I am eminently qualified to speak from experience about a variety of dumpster fires.
ICS DFIR at Dragos, martial artist, marksman, humanist, level 14 Neutral Good rogue, USAF retired. I post *very serious* things about infosec. Thoughts my own. Enby. ๐ณ๏ธโ๐
Open-source tool maker/hacker. Author of gron, anew, and a dozen dinky security tools. He/him. Tools: http://github.com/tomnomnom
Hacker for hire at @specterops.bsky.social
Blog: https://blog.xpnsec.com
Researcher @SpecterOps. Coding towards chaotic good while living on the decision boundary. #dontbanequality
hacker, maldev, pokemon irl
Team Lead Kovert AS, previously Red Team TrustedSec, terrible creator of InfoSec content ๐นOpinions are my own and not the views of my employer.
Head of Red team @ IBM X-Force. Black Hat Review Board. Founder and co-organizer of Offensive AI Con. Co-Founder of RemoteThreat. inveni et usurpa
Father / Husband / COO at SpecterOps
Federico, creating games and helping developers do the same ๐ซถ๐ป
Godot & Unity // โText Animator for Unityโ // gamedev blog // #unitytips and more. Head of @team.febucci.com
website: febucci.com
tutorials: blog.febucci.com
Formerly queencynethryth | She/her ๐ฉโ๐ป | No to GenAI! ๐
โโ๏ธ | Trans rights! | Demisexual ๐ค๐ค๐ | I like ๐ป๐๐ฎ๐ชก๐๐ฎ
Personal site/blog: cynethryth.com
Kerberoast Guy โข RedSiege CEO โข Hater of Pants โข Former SANS 560 Author, Senior Instructor โข Packers owner โข Work Req: http://redsiege.com/contact
Writer, web developer and consultant based in Hveragerรฐi, Iceland. Lapsed Interactive Media Academic. Webby Tech Stuff and webby book stuff.
https://www.baldurbjarnason.com/
https://softwarecrisis.dev/