TrueCyber Blog
Cybersecurity Research & Insights
Technical deep-dives on red team operations, EDR evasion, payload development, offensive tooling, and the operator mindset - written by practitioners who still run engagements.
The Reverse Engineering Toolkit: CallHook, TrueDiffing, ExportFinder and NetHook
A binary will not explain itself. Here is how CallHook, TrueDiffing and ExportFinder answer the questions every reverser actually asks - what it calls, what changed, and what it really imports - and how they fit together with NetHook for real-time debugging.
Read article →NereusPulse: Turning 15 Years of Offense Into Real-Time Detection
NereusPulse is my attempt to automate everything I have learned in 15 years of offensive security into a tool that helps SOC and detection teams hunt by real-time behavioural pattern instead of chasing one actor's IOCs. Here is the idea, the technical design, the EDR and Entra ID connectors, and how you can try it free while I fine-tune it.
Read article →The Danger of Default: Entra ID Permissions and AzureRedOps
Azure Entra ID ships with permissive defaults that let any user register applications and read the whole directory. Here is how AzureRedOps weaponises that with a new register-app feature, and why you should lock it down today.
Read article →Thick-Client Penetration Testing with NetHook
Traditional proxies fall short when testing Windows thick clients that pin certificates or ignore proxy settings. NetHook hooks traffic before encryption, making it the ideal tool for this class of testing.
Read article →Welcome to the New TrueCyber Platform
TrueCyber has a new home: a redesigned platform bringing the blog, our Windows tooling, and live and self-paced training together in one place. Here is what is live today and what is coming next.
Read article →No articles match your search.