logo

Red Teaming: A Story From the Trenches

ID: 72a353ad-fb71-519c-9faf-2cbb59a19fab

STIX ID: report--72a353ad-fb71-519c-9faf-2cbb59a19fab

Feed Name: Black Hills Infosec Blog

Threat Score
55/100

Date Published: 2024-04-18

Date Updated: 2026-04-27

Author: BHIS

...
...

A red-team narrative describing how testers defeated strict Windows application allowlisting by adapting the 'SquiblyDoo' REGSVR32/scrobj technique into a custom DLL called WEvade that directly executed base64-encoded shellcode fetched from a file or web server. The operators delivered the payload using a Bash Bunny/USB to an unlocked workstation during a physical penetration test and achieved a command channel despite USB-connection detection alerts, illustrating both a technical bypass and the role of human/process weaknesses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.