MCMarco Carolainblog.redghostops.com·6d ago · 5 min readI got tired of blurring passwords in Preview, so I built a screenshot tool for pentestersEvery engagement ends the same way for me. I have somewhere between fifty and two hundred screenshots scattered across the Desktop, Downloads and a folder called evidence that I swear I'll organize ne10
MCMarco Carolainblog.redghostops.com·Sep 8 · 8 min readGhostLoot part 2: the Microsoft cookie mess, the inbox, and the Google wallPart 1 got the loot out of Evilginx's session list. Part 2 is what I learned the hard way after that: which Microsoft cookie is actually money, which "TTL" is a fiction, how the panel had to stop bein00
MCMarco Carolainblog.redghostops.com·Sep 6 · 7 min readI got tired of Evilginx's session list, so I built GhostLootRun an AiTM campaign with Evilginx for a day and you know the drill. You SSH into the box, type sessions, and a wall of rows scrolls by. Bots. Scanners. The same target who clicked five times. Landing22IM
MCMarco Carolainblog.redghostops.com·May 8 · 10 min readSAM-EXFIL: Credential Extraction via Raw NTFS Volume ReadsAs red teamers regularly operating against mature Windows environments, we frequently encounter endpoint detection and response solutions that monitor access to Windows credential hive files at the AP31M
MCMarco Carolainblog.redghostops.com·Apr 12 · 18 min readRexLDR | Anatomía de un Shellcode Loader Moderno: Técnicas, Evidencia y Perspectiva DualEl 90% de los loaders mueren en los primeros 30 segundos Dato de contexto antes de entrar en materia: según la telemetría de Microsoft Cyber Signals 2025, más del 90% de los intentos de inyección de 10