NetNTLMv1 Is Dead. Long Live NetNTLMv1.
Fitting lossless rainbow tables on a 4 TB disk and cracking NetNTLMv1 with WebGPU and ntlmrain. Google’s release of the NetNTLMv1 rainbow tables made it much more practical to recover an NT hash from...
View ArticleRed Team AI Skills
Today, SpecterOps released a new open-source skills marketplace for offensive security research and red team operations. We are proud to have collaborated on this project over the last few weeks and...
View ArticleInfrared: How External Researchers Bring Tools into OST
In this blog, we want to do more than point at a new capability inside OST. We want to show how external researchers can bring their own tools into the platform, using InfraRED as a practical example...
View ArticleNew Mouse in the House: Zero-Point Security Training Joins the Fortra Family
For those who don’t know me, my name is Daniel Duggan, known online as RastaMouse. I spent over a decade working as a penetration tester and red teamer across the public and private sector, before...
View ArticleIntroducing Cobalt Strike Research Labs
This is a joint blog written by Stan Hegt, Pieter Ceelen, and Will Burgess. Today, we’re launching Cobalt Strike Research Labs (CS:RL), a new Fortra offering that unites the research expertise of the...
View ArticlemacOS JIT Memory
The macOS Hardened Runtime prevents execution of unsigned code. Unsigned executables will not run, regardless of compilation settings. Processes cannot load unsigned shared libraries into apps with...
View ArticleRed Macros Factory Is Joining OST (And So Am I!)
Hey everyone! I’m Mariusz Banach (mgeeky) and I’m excited to introduce myself as the newest member of the Outflank team. For those who don’t know me, I’ve spent years in the trenches as a red teamer...
View ArticlePatchGuard Peekaboo: Hiding Processes on Systems with PatchGuard in 2026
Introduction I spent a few weeks (and could have spent even more) trying to find a reliable trick to intercept kernel activity while HVCI was breathing down my neck. Almost every approach I tried...
View ArticleLinux Process Injection via Seccomp Notifier
This post demonstrates the use of seccomp user notifications to inject a shared library into a Linux process. I haven’t seen this combination documented as a process injection technique before, and it...
View ArticleTraining Specialist Models: Automating Malware Development
This post complements the presentation I gave at Black Hat USA 2025. Can a small, self-hosted LLM outperform state-of-the-art models at evasive malware development?In this technical deep dive, we...
View ArticleAccelerating Offensive R&D with Large Language Models
At Outflank, we continually seek ways to accelerate our research and development efforts without compromising quality. In this pursuit, we’ve begun integrating large language models (LLMs) into our...
View ArticleAsync BOFs –“Wake Me Up, Before You Go Go”
Asynchronous BOFs: Enabling New Use Cases for Red Team Operators The introduction of Beacon Object Files (BOFs) by Cobalt Strike in 2020 revolutionized the capabilities of red team operators and...
View ArticleBOF Linting for Accelerated Development
Creating Beacon Object Files (BOFs) allows operators to extend the functionality of a C2 framework, though their development may sometimes involve hidden complexities that only become apparent after...
View ArticleSecure Enclaves for Offensive Operations (Part II)
This blog post is the second part in a series about using Secure Enclaves for Offensive Operations. The first part discussed the basics of how enclaves work, provided some ideas on how to develop your...
View ArticleSecure Enclaves for Offensive Operations (Part I)
This blog post was co-authored by Matteo Malvica (Researcher at OffSec and External OST developer) and Cedric Van Bockhaven (OST developer and researcher at Outflank). This article is the first in a...
View Article2024 Wrapped: Outflank’s Top Tracks
As 2024 nears its end, we feel it is a great time to look back at what we achieved in 2024.TLDR: No one would call this a quiet year for Outflank. OST Releases: New Tools and Major Releases 22...
View ArticleIntroducing Early Cascade Injection: From Windows Process Creation to...
By Guido Miggelenbrink at Outflank Introduction In this blog post we introduce a novel process injection technique named Early Cascade Injection, explore Windows process creation, and identify how...
View ArticleWill the real #GrimResource please stand up? – Abusing the MSC file format
In this blog post we describe how the MSC file format can be leveraged to execute arbitrary code via MMC (Microsoft Management Console) for initial access or lateral movement purposes. A sample...
View ArticleIntroducing Outflank C2 with Implant Support for Windows, macOS, and Linux
We have rebranded our commercial C2 framework from Stage1 to Outflank C2 to reflect its continued growth and functionality, including native implant support for Windows, macOS, and Linux. The...
View ArticleTraining Specialist Models: Automating Malware Development
This post complements the presentation I gave at Black Hat USA 2025. Can a small, self-hosted LLM outperform state-of-the-art models at evasive malware development?In this technical deep dive, we...
View Article