logo

Red Teamer’s Cookbook: BYOI (Bring Your Own Interpreter)

ID: 971b28a1-5f3b-5cf0-871e-1ab8469317c9

STIX ID: report--971b28a1-5f3b-5cf0-871e-1ab8469317c9

Feed Name: Black Hills Infosec Blog

Date Published: 2020-02-03

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post introduces and demonstrates BYOI (Bring Your Own Interpreter) tradecraft: embedding a .NET scripting language (Boolang/Boo) inside PowerShell to dynamically compile and execute code in-memory, bypass AMSI and ScriptBlock logging, and implement a simple HTTP-based C2 for delivering source. It covers .NET fundamentals, a step-by-step PoC implant, detection difficulties, and suggested defensive mitigations to raise the bar against this technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.