__ __ ____ ___ __ _______ _ __
/ //_// __ \/ | / //_/__ // | / /
/ ,< / /_/ / /| | / ,< /_ </ |/ /
/ /| |/ _, _/ ___ |/ /| |___/ / /| /
/_/ |_/_/ |_/_/ |_/_/ |_/____/_/ |_/
Maor Sabag - Red Team Operator & Malware Developer
Red Team Operator focused on Windows internals, evasion research, and offensive tool development. Building C2 implants, EDR bypasses, and lateral movement tools.
- TrueSightKiller
- AV/EDR killer leveraging vulnerable kernel drivers
- SideLoadingDLL
- DLL sideloading for stealthy payload execution
- Paruns-Fart
- NTDLL unhooking to bypass EDR userland hooks
- Adaptix-StealthPalace
- Crystal Palace RDLL for Adaptix C2 - Ekko sleep mask, PICO IAT hooks, per-section permission restore
- adaptix-telegram-bot
- Telegram interface for Adaptix C2 teamserver management
- impacket-jump
- Lateral movement via remote service staging, built on Impacket
- interactive-execute-shellcode
- Remote shellcode injection with named pipe output capture
- SafeCrypt
- Academic ransomware simulation - AES-256 + asymmetric key exchange
Latest post: Sleeping Beauty: Putting Adaptix to Bed with Crystal Palace - Crystal Palace RDLL with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration for Adaptix C2.


