Raphael Mudge
@raphaelmudge.bsky.social
📤 261
📥 15
📝 195
Riding around in the breeze. Security Thinker. Hacker. USAF Veteran.
https://aff-wg.org
reposted by
Raphael Mudge
Calzone
4 days ago
I've been obsessed with
@raphaelmudge.bsky.social
's Crystal Palace since I learned about it at Beacon earlier this month, so... here's a WIP PICO I wrote to hook functions with hardware breakpoints đź‘€
github.com/ofasgard/har...
loading . . .
GitHub - ofasgard/hardware-breakpoint-pico: A PICO for Crystal Palace that implements hardware breakpoint hooking.
A PICO for Crystal Palace that implements hardware breakpoint hooking. - ofasgard/hardware-breakpoint-pico
https://github.com/ofasgard/hardware-breakpoint-pico
0
3
1
I'll unpack a few thoughts on this...
add a skeleton here at some point
5 days ago
1
4
1
Analysis of a Ransomware Breach
aff-wg.org/2025/09/26/a...
Breach analysis? Breach intelligence? Industry critique? Fee-only ransomware negotiator? 100% efficacy? The story of how Microsoft worked an old problem, fucked it up, we malign the guy who told us, they fixed it, and it wasn't fixed? PtH?
7 days ago
0
13
7
reposted by
Raphael Mudge
Red Siege
15 days ago
Our CEO
@timmedin.bsky.social
offers his thoughts on what exactly led to the Ascension breach in this follow-up article from Ars Technica:
arstechnica.com/security/202...
#hacking
#infosec
#cybersecurity
loading . . .
How weak passwords and other failings led to catastrophic breach of Ascension
A deep-dive into Active Directory and how “Kerberoasting” breaks it wide open.
https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/
0
4
3
reposted by
Raphael Mudge
_RastaMouse
19 days ago
[BLOG] I wrote a short post on using the Crystal Palace API from an external Java program.
rastamouse.me/crystal-pala...
loading . . .
Crystal Palace API
Crystal Palace provides two command-line tools, called link and piclink, which are used with a specification file to combine a reflective loader with one or more capabilities (DLLs and/or COFFs). lin...
https://rastamouse.me/crystal-palace-api/
0
5
1
""I'm also interested in looking at the Java API a bit more to see how one might build a merged capability in a more progammatic fashion (imagine a GUI where you configure & build a capability by checking/unchecking "features" to include in the final output).""
add a skeleton here at some point
20 days ago
0
1
2
reposted by
Raphael Mudge
Tim Medin
22 days ago
In response to Senator Ron Wyden's letter to the FTC, I have put together my comments on Kerberoasting and RC4.
redsiege.com/blog/2025/09...
loading . . .
https://redsiege.com/blog/2025/09/kerberoasting-microsoft-and-a-senator/
1
10
3
COFFing out the Night Soil
aff-wg.org/2025/09/10/c...
A COFF-focused Crystal Palace update: * internal COFF normalization & section group merging * Crystal Palace can now export COFF * I added COFF merging to the spec language too Linker stuff.
loading . . .
COFFing out the Night Soil
I’m back with another update to the Tradecraft Garden project. Again, this release is focused on the Crystal Palace linker. My priority in this young project is to build the foundation first, then …
https://aff-wg.org/2025/09/10/coffing-out-the-night-soil/
22 days ago
0
11
6
reposted by
Raphael Mudge
Tim Medin
22 days ago
The issue isn't as much RC4 as it is bad passwords. While RC4 isn't good, other encryption does *not* prevent Kerberoasting. AES128 and AES256 just slow down the attack by ~100-170x. If the password is really bad, 170x is meaningless.
@matthewdgreen.bsky.social
arstechnica.com/security/202...
loading . . .
Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”
Wyden says default use of RC4 cipher led to last year’s breach of health giant Ascension.
https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/
1
4
1
If you're in London, Will Burgess (
x.com/joehowwolf
) is speaking at Beacon %25 on "Linkers and Loaders: Experiments with Crystal Palace" this Thursday.
www.eventbrite.co.uk/e/beacon-25-...
beac0n.org
From his X: "If you enjoy filthy PIC tradecraft it may be of interest!"
loading . . .
Beacon %25
The fourth year of Beacon: London's home of hackers, hunters and EDR dodgers.
https://www.eventbrite.co.uk/e/beacon-25-tickets-1438391440519
23 days ago
0
6
5
@hdm.io
A Pirate's Guide to Snake Oil & Security (May 2025)
www.runzero.com/resources/pi...
""So I spent most of my life doing vulnerability research in some form... this is an area I've spent a whole too much of my life caring about and I feel like it's not in a great state today""
loading . . .
NSEC Keynote: A Pirate's Guide to Snake Oil & Security
Watch HD Moore's keynote at NSEC, where you are taken on a satirical voyage through the crowded world of vulnerability management.
https://www.runzero.com/resources/pirates-guide-to-snake-oil-security/
about 1 month ago
1
6
0
Server Outage: My OSS project websites (e.g., Tradecraft Garden, Sleep, etc.) are down due to a maintenance window at my VPS host. They're working it.
about 1 month ago
1
4
0
reposted by
Raphael Mudge
Greg Otto
2 months ago
Jen Easterly writes a post on LinkedIn addressing her position at West Point being rescinded: "A casualty of casually manufactured outrage that drowned out the quiet labor of truth and the steady pulse of integrity."
www.linkedin.com/pulse/harder...
loading . . .
The Harder Right
I spent 25 years in uniform, including four as a cadet at the United States Military Academy at West Point and two and a half more teaching economics and national security at West Point’s Department o...
https://www.linkedin.com/pulse/harder-right-jen-easterly-hi1be/
2
47
39
I just updated my 25+ year old IRC client, jIRCii. Curious about Aggressor Script's ancestor? It's here. Update improves IRC over SSL/TLS UX, fixes some bugs, tightens some screws, and fixes build to compile on OpenJDK 10+.
jircii.dashnine.org/download/
CC
@hagiagraphe.bsky.social
loading . . .
jIRCii - Java IRC Client
jIRCii is a fully scriptable internet relay chat client for Windows, MacOS X, and Linux. It's free too
https://jircii.dashnine.org
2 months ago
3
6
1
reposted by
Raphael Mudge
_RastaMouse
2 months ago
Published a small collection of PIC loaders for Cobalt Strike, based on my experiments with Crystal Palace.
github.com/rasta-mouse/...
loading . . .
GitHub - rasta-mouse/Crystal-Loaders: A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike
A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike - rasta-mouse/Crystal-Loaders
https://github.com/rasta-mouse/Crystal-Loaders
0
4
2
reposted by
Raphael Mudge
_RastaMouse
2 months ago
[BLOG] Here's the post - I demonstrate my QoL improvements for working with the TCG codebase. This includes vscode with intellisense support, and producing debug builds for use in WinDbg.
rastamouse.me/debugging-th...
add a skeleton here at some point
1
4
2
@rastamouse.me
digging more into Crystal Palace and demonstrates some of the cross-linking possibilities. I'll admit, I got a little nerd-sniped here, because I'm *not* thinking greatly about "the" way to decompose a complex/modular capability (e.g., a C2 agent). Thread below has my thoughts...
add a skeleton here at some point
2 months ago
1
5
0
I loved this keynote. But, also felt sadness. Where there is tribe and purpose in our uniqueness in the "hacker community"--there's also a capacity & indifference for cruelty to each other too. I liken it to a smiling group with cannibals present. Room goes dark. Someone disappears. No one cares why
add a skeleton here at some point
3 months ago
0
0
0
I fixed the login required on my PIC fundamentals Vimeo video. In this go around, I'm experimenting with keeping control of my online content (e.g., no GitHub/YouTube, I pay to host it, etc.) Less algorithm spread, but ideally easier to access w/o ads. Back fired this time. I'm learning as I go.
3 months ago
0
4
0
reposted by
Raphael Mudge
_RastaMouse
3 months ago
Hooking arbitrary BOFs via
@raphaelmudge.bsky.social
's Crystal Palace is very cool. I'm going to explore more to see if I can rip out the SleepMask and BeaconGate into their own PICOs, rather than using the official BOF codebases.
1
5
1
Position Independent Code (PIC) Development Crash Course. My July 2025 overview of PIC writing fundamentals. Don't know why jump tables are bad? Got a __chkstk relocation error? Watch this video.
#GoodLuckAndHappyHacking
vimeo.com/1100089433/d...
loading . . .
PIC Development Crash Course
Some helpful content for writing position independent code.
https://vimeo.com/1100089433/d38da198ba?share=copy
3 months ago
0
9
5
A debate is when two parties, with different perspectives, are on a shared journey to truth. Bad Faith communication, can look like debate, but is a quest to dominate, silence, win, and shut down examination of uncomfortable truths that benefit one party.
consilienceproject.org/the-endgames...
loading . . .
The Endgames of Bad Faith Communication - The Consilience Project
https://consilienceproject.org/the-endgames-of-bad-faith-communication/
3 months ago
0
4
0
Taking them to the SHITTER: an analysis of vendor abuse of security research in-the-wild
aff-wg.org/2025/07/13/t...
(There is no benefit modulating my voice for anyone's comfort. This is my fair take, but unapologetic truth. This phenomena has gone unchecked for too long)
3 months ago
1
10
7
Well, latest blog post went live. I tried to schedule for tomorrow, but ended up setting the date to last week. Valid mistake :) So blog subscribers got the content already (although wrong permalink to actual post). So, it's live. I'll come up with something clever to promote it here tomorrow.
3 months ago
0
6
0
Tradecraft Garden: Tilling the Soil
aff-wg.org/2025/07/09/t...
Some updates to... the Tradecraft Garden and Crystal Palace. Info in the đź§µ below:
loading . . .
Tradecraft Garden: Tilling the Soil
Today, I’m releasing another update to the various Tradecraft Garden projects. This update is a dose of Future C2 and some cool updates to the Crystal Palace tech. Here’s the latest: Code Mutation …
https://aff-wg.org/2025/07/09/tradecraft-garden-tilling-the-soil/
3 months ago
1
12
6
Congratulations
x.com/c5pider
on the release of Havoc Professional. A commercial C2 focused on flexibility and modularity.
www.infinitycurve.org/blog/introdu...
loading . . .
Havoc Professional: A Lethal Presence
An introduction to Havoc Professional and Kaine-kit, exploring the advanced features and capabilities that make them lucrative for modern security professionals.
https://www.infinitycurve.org/blog/introduction
3 months ago
1
11
1
Function disco @ The Crystal Palace
3 months ago
0
3
0
Beacon Object Files... Five Years On
aff-wg.org/2025/06/26/b...
I released BOFs with Cobalt Strike 4.1 five years ago. This is some history on the feature and what led to it. My thinking at the time. A few thoughts on current discourse.
loading . . .
Beacon Object Files – Five Years On…
When I was active in the red teaming space, one of my stated goals was to act on problems with solutions that would have utility 5-10 years from the time of their release. This long-term thinking w…
https://aff-wg.org/2025/06/26/beacon-object-files-five-years-on/
3 months ago
0
12
5
@rastamouse.me
continuing to show how to use TCG loaders with Cobalt Strike. This time, post-ex DLLs, and passing pointers to avoid EAF-like detections. He also goes into how to gather section information to pass to a CS post-ex DLL to enable sleep mask-like obfuscation in DLLs that support it.
add a skeleton here at some point
4 months ago
1
6
0
One of my Tradecraft Garden recommendations is to try out the samples as-is then try them with something you like. Here
@rastamouse.me
walks through adopting them to
@cobaltstrike.bsky.social
and shows how to use my linker to dynamically generate UDRLs via Aggressor Script. Good stuff.
add a skeleton here at some point
4 months ago
1
4
0
reposted by
Raphael Mudge
Sean Gallagher
4 months ago
Six years ago, a whole city government got ransomwared and blamed it on the NSA becaise some reporter pointed out the EternalBlue exploit was part of the attacker’s kit …over 2 years after Microsoft pushed patches to prevent its use.
arstechnica.com/information-...
loading . . .
Eternally Blue: Baltimore City leaders blame NSA for ransomware attack
Mayor and council president ask for federal disaster dollars to clean up IT toxic waste.
https://arstechnica.com/information-technology/2019/05/eternally-blue-baltimore-city-leaders-blame-nsa-for-ransomware-attack/
3
38
11
A good day for open source tradecraft, packaged in a usable form, getting put into the conversation.
add a skeleton here at some point
4 months ago
0
3
0
So, here's a little thread on my new open source project: The Tradecraft Garden.
tradecraftgarden.org
It's Crystal Palace, an open-source linker and linker script specialized to writing PIC DLL loaders. And, a corpora of DLL loaders demonstrating design patterns building tradecraft with it.
4 months ago
1
24
15
Planting a Tradecraft Garden
aff-wg.org/2025/06/04/p...
4 months ago
0
3
2
reposted by
Raphael Mudge
_RastaMouse
5 months ago
ICYMI it on the heathen platform, I recently launched a new training portal for Zero-Point. Read more here:
www.zeropointsecurity.co.uk/blog/new-sit...
loading . . .
New Site Launch
https://www.zeropointsecurity.co.uk/blog/new-site-launch
0
7
3
Homesteading the Noosphere by Eric S Raymond: ""I then relate that to an analysis of the hacker culture as a `gift culture' in which participants compete for prestige by giving time, energy, and creativity away.""
www.catb.org/esr/writings...
6 months ago
1
2
0
Post-ex Weaponization: An Oral History
aff-wg.org/2025/04/10/p...
A walk-through of some history on post-ex eco-systems used by CS (PowerShell, Reflective DLLs, .NET, and BOFs). Ends with a coffee conversation talking about magician's guilds, security research, and ideas about what's next.
6 months ago
0
12
9
I attended last week's Pall Mall Process conference in Paris. I wanted to dump a few notes, writing from my perspective as a security researcher, hacker, former entrepreneur, and creator of a well-known C2 platform (one that, importantly, I'm no longer involved with).
6 months ago
1
4
3
If I could have my ideal, professionally satisfying cybersecurity career or foothold-level (e.g., 1-3 months a year) involvement. What would make me happy?
6 months ago
1
4
0
I have something of an agenda as it relates to security research and culture. I will pursue that agenda (partially) through heart warming graphics and super-cute analogies. BEWARE! The CUTE is coming.
6 months ago
0
8
0
Change is constant. When we adapt, it's natural to try and keep today's 'what', but it's folly to forget 'why'. 'why' needs to lead.
7 months ago
0
0
0
Years ago, a friend commented that the free, crazy, ranting, swearing, passionate me was someone people connected with at conferences. I lost my that person, because of... shit. I mean well, I think, I learn (from you)--I like discourse. I'm challenging myself to be... myself again. Wish me luck.
7 months ago
0
11
0
Dig through this timeline and you'll figure out what I'm here to do. I spoke to a commercial leader in the offensive security space last year. My words: you're fucking it up. What I didn't say: I feel compelled, even though I DON'T want the bullshit, to try and fix it. What does all of this mean?
7 months ago
2
23
14
Got a project or tool you want to release? STOP. Only the purest may publish offensive security research... And, we sense a darkness--you have harmed others... || What it's like navigating industry norms on research ethics and good-faith attempts at appeasement
www.youtube.com/watch?v=vulJ...
loading . . .
ONLY THE PUREST MAY MOUNT ME
YouTube video by Dungeon Soup
https://www.youtube.com/watch?v=vulJTr8u2gc
7 months ago
0
1
0
Probably one of my favorite songs I've stumbled on in the last years. End of the Line by Traveling Wilburys. A good reflection on life, participation, staying 'you' around changing trends, and what's next from a post-middle perspective.
www.youtube.com/watch?v=UMVj...
loading . . .
The Traveling Wilburys - End Of The Line (Official 4K Music Video)
YouTube video by OfficialWilburyVEVO
https://www.youtube.com/watch?v=UMVjToYOjbM
7 months ago
0
13
1
The Security Conversation - The value of offensive security work is fully realized by participation in the security conversation.
aff-wg.org/2025/03/13/t...
7 months ago
0
11
6
you reached the end!!
feeds!
log in