Initial Access Operations Part 2: Offensive DevOps
ID: 84f75393-c71b-5ac0-a044-c0f71869e9fa
STIX ID: report--84f75393-c71b-5ac0-a044-c0f71869e9fa
Feed Name: Black Hills Infosec Blog
This blog outlines a GitLab-based CI/CD “Malware as a Service” pipeline that automates the creation of diverse, evasive Windows artifacts for red team initial access, using Dockerized build containers, Windows/Linux runners, and Python-generated child pipelines to deliver unique binaries with obfuscation, ETW/AMSI bypasses, and multiple packaging formats (e.g., MSIX, ClickOnce), alongside hashing/metrics, operator configuration via BuffetConfig.yml, and a discussion of advantages, limitations, and practitioner feedback.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
