<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: lupingQAQ</title>
    <description>The latest articles on DEV Community by lupingQAQ (@lupingqaq).</description>
    <link>https://dev.to/lupingqaq</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4149829%2F486cf9c3-4968-4f2b-bc38-17017e0a745f.jpg</url>
      <title>DEV Community: lupingQAQ</title>
      <link>https://dev.to/lupingqaq</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/lupingqaq"/>
    <language>en</language>
    <item>
      <title>red-team-skill-tree: a full-stack offensive security reference</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:49:46 +0000</pubDate>
      <link>https://dev.to/lupingqaq/red-team-skill-tree-a-full-stack-offensive-security-reference-4mf7</link>
      <guid>https://dev.to/lupingqaq/red-team-skill-tree-a-full-stack-offensive-security-reference-4mf7</guid>
      <description>&lt;h1&gt;
  
  
  red-team-skill-tree: a full-stack offensive security reference
&lt;/h1&gt;

&lt;p&gt;A comprehensive red team skill reference covering the full offensive-security stack - from anti-attribution and reconnaissance to post-exploitation, malware evasion, cloud-native attacks, and AI-powered offense. Based on a real training curriculum, updated with 2025-2026 APT techniques.&lt;/p&gt;

&lt;h2&gt;
  
  
  Coverage (24 sections)
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;#&lt;/th&gt;
&lt;th&gt;Topic&lt;/th&gt;
&lt;th&gt;Coverage&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Anti-Attribution and Anonymization&lt;/td&gt;
&lt;td&gt;OPSEC, encrypted VMs, anonymous network chains, crypto laundering&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Reconnaissance&lt;/td&gt;
&lt;td&gt;OSINT, SGK, asset platforms, supply-chain mapping, CDN bypass&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;Penetration Testing&lt;/td&gt;
&lt;td&gt;Web app attacks (SQLi/RCE/upload), framework exploits, container escape&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Code Audit&lt;/td&gt;
&lt;td&gt;Java (MyBatis/deserialization/SSTI), PHP (ThinkPHP RCE chains), .NET, memory shells&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Post-Exploitation and Lateral Movement&lt;/td&gt;
&lt;td&gt;AD attacks (Kerberos/delegation/CVEs), credential harvesting, privilege escalation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Host Credential Extraction&lt;/td&gt;
&lt;td&gt;Browser/SSH/RDP/VPN password decryption tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;Social Engineering&lt;/td&gt;
&lt;td&gt;Phishing pretexts, waterholing, malicious payload crafting&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;C2 Development&lt;/td&gt;
&lt;td&gt;Cobalt Strike customization, Godzilla modification, traffic forwarding&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;Malware Evasion&lt;/td&gt;
&lt;td&gt;EDR blinding (driver-level), static/dynamic/traffic evasion, injection techniques&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Forensic Image Recovery&lt;/td&gt;
&lt;td&gt;Linux disk image restoration for evidence analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;AI-Powered Attacks&lt;/td&gt;
&lt;td&gt;Deepfake phishing, LLM-assisted malware, AI infrastructure CVEs, OWASP LLM Top 10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;Cloud-Native Attacks&lt;/td&gt;
&lt;td&gt;Kubernetes escape (runc/eBPF), serverless, CI/CD supply chain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;14-24&lt;/td&gt;
&lt;td&gt;Advanced Techniques&lt;/td&gt;
&lt;td&gt;Modern C2, sleep obfuscation, ADCS (ESC1-16), MFA bypass, zero-trust evasion, OT/ICS, mobile, living-off-the-land&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Files
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;File&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree.md&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Main content - refined skill tree, 24 sections (English)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree.zh-CN.md&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Main content - 24-section reference (Chinese)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree-outline.md&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Original XMind export, raw outline (English)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree-outline.zh-CN.md&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Original XMind export (Chinese)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree.xmind&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;XMind source file&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;red-team-skill-tree.png&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Full-resolution mind map&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Repo: &lt;a href="https://github.com/lupingQAQ/red-team-skill-tree" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/red-team-skill-tree&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>SqlStealthRogue: a zero-probe SQL and NoSQL data dumper</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:49:25 +0000</pubDate>
      <link>https://dev.to/lupingqaq/sqlstealthrogue-a-zero-probe-sql-and-nosql-data-dumper-2m04</link>
      <guid>https://dev.to/lupingqaq/sqlstealthrogue-a-zero-probe-sql-and-nosql-data-dumper-2m04</guid>
      <description>&lt;h1&gt;
  
  
  SqlStealthRogue: a zero-probe SQL and NoSQL injection data dumper
&lt;/h1&gt;

&lt;p&gt;A minimalist, zero-probe SQL/NoSQL injection data dumper. Single entry file, pure Python standard library, no dependencies.&lt;/p&gt;

&lt;h2&gt;
  
  
  Concept
&lt;/h2&gt;

&lt;p&gt;SqlStealthRogue is a scalpel, not a swiss-army knife: given a known injection point and a known database, table, and columns, it extracts data at high speed with zero negotiation and zero reconnaissance traffic. sqlmap - even with &lt;code&gt;-D/-T/-C&lt;/code&gt; pinned - still fires requests for DBMS fingerprinting, version detection, privilege/table enumeration, WAF detection and technique polling. SqlStealthRogue does the opposite: &lt;strong&gt;every single request it sends is a data-extraction request.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Zero extra requests
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Behavior&lt;/th&gt;
&lt;th&gt;SqlStealthRogue&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DBMS fingerprint / version probing&lt;/td&gt;
&lt;td&gt;none&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Privilege / schema enumeration&lt;/td&gt;
&lt;td&gt;none (you already know the target)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WAF detection / technique polling&lt;/td&gt;
&lt;td&gt;none (&lt;code&gt;--dbms&lt;/code&gt; + &lt;code&gt;--technique&lt;/code&gt;, specify and go)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;True-mark calibration requests&lt;/td&gt;
&lt;td&gt;none (row termination rides on extraction requests)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Every request sent&lt;/td&gt;
&lt;td&gt;is a data-extraction request&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  High-speed extraction (measured on real engines)
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Optimization&lt;/th&gt;
&lt;th&gt;Measured effect&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Bit-parallel blind engine (&lt;code&gt;char &amp;amp; mask&lt;/code&gt;, 8 concurrent bits)&lt;/td&gt;
&lt;td&gt;5.35x faster, request count identical to serial binary search&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;HTTP keep-alive, thread-local connections&lt;/td&gt;
&lt;td&gt;5.6x faster (auto-downgrades on HTTP/1.0 targets, zero penalty)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Error-mode adaptive chunk prefetch&lt;/td&gt;
&lt;td&gt;long values fetched in one batch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PG/MSSQL large chunks (error messages carry &amp;gt;=800 chars, measured)&lt;/td&gt;
&lt;td&gt;600-char value: 22 -&amp;gt; 6 requests&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;UNION mode&lt;/td&gt;
&lt;td&gt;whole table in 1 request&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Custom WAF-bypass plugins (tamper chains)
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# 13 sqlmap-compatible tampers built in; compose in order; zero extra traffic&lt;/span&gt;
python SqlStealthRogue.py &lt;span class="nt"&gt;--tamper&lt;/span&gt; &lt;span class="s2"&gt;"randomcase,between,space2comment"&lt;/span&gt; ...

&lt;span class="c"&gt;# Custom plugin: one .py file with one tamper() function&lt;/span&gt;
python SqlStealthRogue.py &lt;span class="nt"&gt;--tamper&lt;/span&gt; mybypass &lt;span class="nt"&gt;--tamper-dir&lt;/span&gt; /path/to/tampers ...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Built-in tampers: &lt;code&gt;space2comment&lt;/code&gt; &lt;code&gt;space2plus&lt;/code&gt; &lt;code&gt;space2randomblank&lt;/code&gt; &lt;code&gt;between&lt;/code&gt; &lt;code&gt;equaltolike&lt;/code&gt; &lt;code&gt;randomcase&lt;/code&gt; &lt;code&gt;charencode&lt;/code&gt; &lt;code&gt;chardoubleencode&lt;/code&gt; &lt;code&gt;halfversionedmorekeywords&lt;/code&gt; &lt;code&gt;apostrophemask&lt;/code&gt; &lt;code&gt;percentage&lt;/code&gt; &lt;code&gt;unionalltounion&lt;/code&gt; &lt;code&gt;xforwardedfor&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Minimal-blast-radius abort on misconfiguration
&lt;/h2&gt;

&lt;p&gt;A wrong parameter never floods the target - the cost of a mistake is capped at "first row, first value":&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Misconfiguration&lt;/th&gt;
&lt;th&gt;Packets actually sent&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Statically invalid args / unknown tamper / dbms x technique mismatch&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Injection point unreachable&lt;/td&gt;
&lt;td&gt;&amp;lt;= 2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Template or true-mark syntax error&lt;/td&gt;
&lt;td&gt;8-16&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Always-true true-mark / always-matching regex (sentinel guards abort)&lt;/td&gt;
&lt;td&gt;~128 (would be 16,384+ without guards)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bad UNION template&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  12-engine real-machine verification matrix
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Engine&lt;/th&gt;
&lt;th&gt;error&lt;/th&gt;
&lt;th&gt;bool&lt;/th&gt;
&lt;th&gt;time&lt;/th&gt;
&lt;th&gt;prefix&lt;/th&gt;
&lt;th&gt;union&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;MySQL 8&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PostgreSQL 14&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MSSQL 2022&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SQLite&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Redis&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;partial&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MongoDB 7&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;openGauss 5&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OceanBase CE&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Oracle 23ai&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Elasticsearch 8&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;partial&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Milvus 2.4&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;pgvector&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;yes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Repo: &lt;a href="https://github.com/lupingQAQ/SqlStealthRogue" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/SqlStealthRogue&lt;/a&gt;&lt;/p&gt;

</description>
      <category>database</category>
      <category>python</category>
      <category>security</category>
      <category>sql</category>
    </item>
    <item>
      <title>impacket-programming-manual: writing your own domain-penetration scripts</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:43:19 +0000</pubDate>
      <link>https://dev.to/lupingqaq/impacket-programming-manual-writing-your-own-domain-penetration-scripts-1hon</link>
      <guid>https://dev.to/lupingqaq/impacket-programming-manual-writing-your-own-domain-penetration-scripts-1hon</guid>
      <description>&lt;h1&gt;
  
  
  impacket-programming-manual: writing your own domain-penetration scripts
&lt;/h1&gt;

&lt;p&gt;A book-length, source-code-driven guide to developing your own domain-penetration scripts on top of impacket - not another walkthrough of &lt;code&gt;secretsdump.py&lt;/code&gt; / &lt;code&gt;psexec.py&lt;/code&gt; flags.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this manual exists
&lt;/h2&gt;

&lt;p&gt;Almost every public exploit for recent Active Directory vulnerabilities was built directly on impacket modules: &lt;code&gt;sam-the-admin&lt;/code&gt;, &lt;code&gt;CVE-2022-33679&lt;/code&gt;, &lt;code&gt;noPac&lt;/code&gt;, &lt;code&gt;Zerologon&lt;/code&gt; tooling, &lt;code&gt;PetitPotam&lt;/code&gt;-style relay chains. Yet nearly all existing articles only explain how to run the example scripts. This manual fills the gap the other way around: it walks module by module through the impacket source tree, so when the next domain vulnerability drops you can grab impacket and write your own PoC fast.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Author: Lu Ping&lt;/li&gt;
&lt;li&gt;Length: ~5,400 lines, 9 chapters, 6 parts&lt;/li&gt;
&lt;li&gt;Covers: LDAP, Kerberos (krb5), GSS-API/SPNEGO, DCE/RPC (NDR, EPM, transport), 20+ MS protocol modules, DCOM and WMI, the support libraries, and the impacket 0.12-0.14 additions&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What's inside
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Part&lt;/th&gt;
&lt;th&gt;Chapter&lt;/th&gt;
&lt;th&gt;Content&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;I. Preliminaries&lt;/td&gt;
&lt;td&gt;Ch.1 impacket overview and directory layout&lt;/td&gt;
&lt;td&gt;Where every module lives in the source tree&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;Ch.2 &lt;code&gt;structure.py&lt;/code&gt; - universal serialization base&lt;/td&gt;
&lt;td&gt;The base class behind every protocol packet structure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;II. Authentication and Directory&lt;/td&gt;
&lt;td&gt;Ch.3 LDAP (&lt;code&gt;ldap&lt;/code&gt;)&lt;/td&gt;
&lt;td&gt;Directory queries, ACL structures, Global Catalog&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;Ch.4 Kerberos (&lt;code&gt;krb5&lt;/code&gt;)&lt;/td&gt;
&lt;td&gt;Tickets, ccache/keytab, PAC, GSS-API and SPNEGO&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;III. DCE/RPC&lt;/td&gt;
&lt;td&gt;Ch.5 &lt;code&gt;dcerpc&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;RPC basics (NDR, rpcrt, EPM, transport) + 20+ interface modules in 5 functional groups (SAMR, NRPC, LSAD, RRP, SRVS, RPRN/PAR, TSCH, BKRP, DRSUAPI...)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IV. DCOM and WMI&lt;/td&gt;
&lt;td&gt;Ch.6 MS-DCOM&lt;/td&gt;
&lt;td&gt;COM/DCOM programming, dcomrt, oaut/comev/scmp/vds/wmi submodules&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;V. Support libraries&lt;/td&gt;
&lt;td&gt;Ch.7 &lt;code&gt;common&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;SMB2/3, DPAPI, NTDS (ese), TDS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VI. New interfaces and case studies&lt;/td&gt;
&lt;td&gt;Ch.8 interfaces added in 0.12-0.14&lt;/td&gt;
&lt;td&gt;ICPR (AD CS certificate enrollment), GKDI (group key distribution), NEGOEX, RAA (remote authorization), SCMR, plus &lt;code&gt;acl.py&lt;/code&gt; and &lt;code&gt;dpapi_ng.py&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;Ch.9 case studies&lt;/td&gt;
&lt;td&gt;BadSuccessor (CVE-2025-53779) and CVE-2025-33073 - PoC walk-throughs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Case studies woven through the chapters
&lt;/h2&gt;

&lt;p&gt;Zerologon (CVE-2020-1472) in nrpc; PrinterBug / PrintNightmare in rprn/par; CVE-2019-1040 NTLM MIC bypass in gssapi; Exchange RPC-over-HTTP relay (rpcmap / ProxyRelay); Akamai's "Cold Hard Cache" RPC security-callback bypass; WMI persistence (wmipersist); golden PAC forging. In Part VI: BadSuccessor (CVE-2025-53779), which abuses the Windows Server 2025 dMSA account type, and CVE-2025-33073, the reflective relay that yields SYSTEM on any host without SMB signing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlights
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Source-level, not example-level.&lt;/strong&gt; Every chapter reads the actual impacket source: &lt;code&gt;getKerberosTGT&lt;/code&gt;/&lt;code&gt;getKerberosTGS&lt;/code&gt; internals, ccache/keytab binary layouts, &lt;code&gt;DCERPCTransportFactory&lt;/code&gt; dispatch, &lt;code&gt;DCOMConnection&lt;/code&gt;/&lt;code&gt;INTERFACE&lt;/code&gt;/&lt;code&gt;IRemUnknown&lt;/code&gt; object model, &lt;code&gt;IWbemServices&lt;/code&gt; method tables.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Annotated code excerpts.&lt;/strong&gt; Long listings are compressed to key code paths with step-numbered annotations, so you see the flow at a glance instead of scrolling through hundreds of lines of boilerplate.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Upstream-verified quotes.&lt;/strong&gt; All cited code was checked against the current fortra/impacket master; known upstream quirks (the &lt;code&gt;par.py&lt;/code&gt; opnum 39 tuple, &lt;code&gt;hept_map&lt;/code&gt; spelling, &lt;code&gt;MimiUnbind&lt;/code&gt; vs &lt;code&gt;MiniUnbind&lt;/code&gt;) are preserved and annotated instead of silently "fixed".&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Formats
&lt;/h2&gt;

&lt;p&gt;English edition (&lt;code&gt;impacket_programming_manual_EN.pdf&lt;/code&gt;) and Chinese edition (&lt;code&gt;impacketç¼–ç¨‹æ‰‹å†Œ.pdf&lt;/code&gt;), both included, plus the source-first chapters.&lt;/p&gt;

&lt;p&gt;Repo and docs: &lt;a href="https://github.com/lupingQAQ/impacket-programming-manual" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/impacket-programming-manual&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>python</category>
      <category>security</category>
    </item>
    <item>
      <title>dotnet-memshell: three .NET memory shells at three insertion positions</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:42:56 +0000</pubDate>
      <link>https://dev.to/lupingqaq/dotnet-memshell-three-net-memory-shells-at-three-insertion-positions-36c9</link>
      <guid>https://dev.to/lupingqaq/dotnet-memshell-three-net-memory-shells-at-three-insertion-positions-36c9</guid>
      <description>&lt;h1&gt;
  
  
  dotnet-memshell: three .NET memory shells at three distinct insertion positions
&lt;/h1&gt;

&lt;p&gt;Three .NET memory shells at three different insertion positions - single-file payloads, armed by one deserialization, invisible to unmarked traffic.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why these are different
&lt;/h2&gt;

&lt;p&gt;Most public .NET memory shells (module, handler, route, VirtualPathProvider) live inside the HTTP request pipeline at already-known positions. dotnet-memshell spreads across three different layers instead: the pipeline event layer (with pool broadcast), the HTTP-to-WebSocket upgrade point (connection takeover - the .NET port of the WebSocket memory-shell idea), and an already-registered Remoting channel (container-style endpoint registration).&lt;/p&gt;

&lt;p&gt;All three ride the target's existing endpoints: no new port, no &lt;code&gt;web.config&lt;/code&gt; change, no file on disk.&lt;/p&gt;

&lt;h2&gt;
  
  
  The three shells
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;#&lt;/th&gt;
&lt;th&gt;Shell&lt;/th&gt;
&lt;th&gt;Insertion position&lt;/th&gt;
&lt;th&gt;Trigger&lt;/th&gt;
&lt;th&gt;Minimum privilege&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;HttpModuleShell&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;HttpApplication&lt;/code&gt; module-event pipeline&lt;/td&gt;
&lt;td&gt;any request with an &lt;code&gt;MSH-Cmd: &amp;lt;cmd&amp;gt;&lt;/code&gt; header&lt;/td&gt;
&lt;td&gt;default app-pool identity&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;WsTakeoverShell&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;HTTP-to-WebSocket upgrade transition&lt;/td&gt;
&lt;td&gt;handshake with subprotocol &lt;code&gt;msh&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;app-pool identity + integrated pipeline + WS feature&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;RemotingUriShell&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;AppDomain-global URI table of an existing Remoting channel&lt;/td&gt;
&lt;td&gt;remoting call to &lt;code&gt;&amp;lt;channel&amp;gt;/msh&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;app-pool identity + business hosts Remoting&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HTTP.sys / IIS
 +- ASP.NET request pipeline
     +- module events (BeginRequest...)      &amp;lt;- #1 HttpModuleShell
     +- routing / VPP / handler / endpoint    (known families)
     +- upgrade point (HTTP-&amp;gt;WS handshake)   &amp;lt;- #2 WsTakeoverShell

in-process protocol stacks
 +- existing Remoting server channel          &amp;lt;- #3 RemotingUriShell
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  What makes them different
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Property&lt;/th&gt;
&lt;th&gt;dotnet-memshell&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;New listening port&lt;/td&gt;
&lt;td&gt;none - #1/#2 ride the site's 80/443, #3 rides the business channel&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;web.config&lt;/code&gt; / registry / URLACL changes&lt;/td&gt;
&lt;td&gt;none (contrast: HttpListener shells need &lt;code&gt;netsh urlacl&lt;/code&gt;, an admin action)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Files dropped&lt;/td&gt;
&lt;td&gt;none - payloads are single &lt;code&gt;.cs&lt;/code&gt; files compiled into the deserialization, assembly loaded from bytes (&lt;code&gt;Location&lt;/code&gt; empty)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Effect on unmarked traffic&lt;/td&gt;
&lt;td&gt;none - every trigger checks a magic marker first and returns immediately&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Pool coverage&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;HttpApplicationFactory._freeList&lt;/code&gt; broadcast - arming only the serving instance misses most requests&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Graceful degradation&lt;/td&gt;
&lt;td&gt;#2 on non-integrated pools catches and passes through (the handshake request still returns 200)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Call chains
&lt;/h2&gt;

&lt;h3&gt;
  
  
  #1 HttpModuleShell
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;delivery deserialization -&amp;gt; E()
 +- HttpContext.Current.ApplicationInstance                 (serving instance)
 +- HttpApplicationFactory._theApplicationFactory._freeList  (pool broadcast)
      per instance:
      +- integrated: GetModuleContainer(&amp;lt;module&amp;gt;)
      |    -&amp;gt; new SyncEventExecutionStep(app, OnRequest)     [reflection]
      |    -&amp;gt; ModuleContainer.AddEvent(BeginRequest, false, step)
      +- classic:    ApplicationStepManager._execSteps append  [append-only]
trigger: request -&amp;gt; BeginRequest -&amp;gt; step -&amp;gt; OnRequest
      +- no MSH-Cmd header -&amp;gt; return (business continues untouched)
      +- header -&amp;gt; cmd.exe /c -&amp;gt; Response.Write -&amp;gt; End
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  #2 WsTakeoverShell
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;same anchor; handler is a strict no-op unless handshake + msh
GET + Upgrade: websocket + Sec-WebSocket-Protocol: msh
 -&amp;gt; IsWebSocketRequest check -&amp;gt; AcceptWebSocketRequest(Duplex)
 -&amp;gt; connection upgraded, request pipeline terminates, duplex stream owned by the loop
 -&amp;gt; Receive(cmd) -&amp;gt; exec -&amp;gt; Send(output) ... until Close frame
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  #3 RemotingUriShell
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;E()
 +- AppDomain.AssemblyResolve  &amp;lt;- bridges byte-loaded assembly (formatter resolves
 |                                well-known types by assembly NAME)
 +- guard: an IChannelReceiver already exists (business hosts remoting)
 +- RegisterWellKnownServiceType(E.Svc, "msh", Singleton)
trigger: remoting client -&amp;gt; tcp://host:&amp;lt;business-port&amp;gt;/msh -&amp;gt; Svc.Exec(cmd)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Notes
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Payloads are delivered as single &lt;code&gt;.cs&lt;/code&gt; source files, compiled into the deserialization payload; the assembly is loaded from bytes, so &lt;code&gt;Assembly.Location&lt;/code&gt; is empty.&lt;/li&gt;
&lt;li&gt;Each trigger checks a magic marker before doing anything, so unmarked business traffic is untouched.&lt;/li&gt;
&lt;li&gt;For .NET Framework 4.5+.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Repo: &lt;a href="https://github.com/lupingQAQ/dotnet-memshell" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/dotnet-memshell&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>dotnet</category>
      <category>security</category>
    </item>
    <item>
      <title>JGD: an autonomous agent for Java deserialization gadget chains</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:35:12 +0000</pubDate>
      <link>https://dev.to/lupingqaq/jgd-an-autonomous-agent-for-java-deserialization-gadget-chains-85i</link>
      <guid>https://dev.to/lupingqaq/jgd-an-autonomous-agent-for-java-deserialization-gadget-chains-85i</guid>
      <description>&lt;h1&gt;
  
  
  JGD (JavaGadgetDigger): an autonomous agent for Java deserialization gadget chains
&lt;/h1&gt;

&lt;p&gt;JavaGadgetDigger is an autonomous agent for Java deserialization research. Point it at a JAR directory and it produces gadget chains and weaponized proof-of-concept payloads, with no intermediate user input.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the last mile matters
&lt;/h2&gt;

&lt;p&gt;For most Java deserialization work, the hard part is the last mile: you have the classpath in front of you, and you need a working chain from an entry point to a dangerous sink. JGD automates that step end to end.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it produces
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Known public chains&lt;/strong&gt; with a four-state determination: &lt;code&gt;PRESENT&lt;/code&gt; / &lt;code&gt;VERSION&lt;/code&gt; / &lt;code&gt;ASSEMBLE&lt;/code&gt; / &lt;code&gt;FIRE&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Novel, unpublished chains&lt;/strong&gt; discovered through static + dynamic analysis with adversarial LLM auditing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Weaponized PoCs&lt;/strong&gt; - serialized payloads with an RCE-closure demo (benign marker file).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;All decisions are internalized: &lt;strong&gt;JARs in, chains out.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Pipeline
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Input: any JAR directory          Output: chains + PoCs

  Known    --&amp;gt;  Bridge    --&amp;gt;  Chain   --&amp;gt;   PoC
  Chains        Discovery      Pairing       Weapon
    |               |               |           |
 signature       bytecode        dynamic     benign
 + version       + CHA graph     contract    payload
 gates           + dispatch      synthesis   + fire
                 edges           + 5 carriers test
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Discovered chains
&lt;/h2&gt;

&lt;h3&gt;
  
  
  T1 - novel entry
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Chain&lt;/th&gt;
&lt;th&gt;Bridge class&lt;/th&gt;
&lt;th&gt;Carrier&lt;/th&gt;
&lt;th&gt;JDK&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;objlongpair-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;org.apache.activemq.artemis.api.core.ObjLongPair&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;17+&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  T2 - new bridge classes
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Vavr family (7 chains):&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Chain&lt;/th&gt;
&lt;th&gt;Bridge class&lt;/th&gt;
&lt;th&gt;Carrier&lt;/th&gt;
&lt;th&gt;JDK&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;tuple1-8-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;io.vavr.Tuple1&lt;/code&gt; ... &lt;code&gt;Tuple8&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;either$left-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.control.Either$Left&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;either$right-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.control.Either$Right&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;option$some-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.control.Option$Some&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;validation$valid-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.control.Validation$Valid&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;validation$invalid-hashmap&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.control.Validation$Invalid&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;hasharraymappedtrie$leafsingleton&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;io.vavr.HashArrayMappedTrie$LeafSingleton&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HashMap rehash&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Spring AOP family (6 chains):&lt;/strong&gt; &lt;code&gt;composablepointcut-hashmap&lt;/code&gt;, &lt;code&gt;methodmatchers$unionmethodmatcher&lt;/code&gt;, &lt;code&gt;methodmatchers$intersectionmethodmatcher&lt;/code&gt;, &lt;code&gt;singletontargetsource-bave&lt;/code&gt;, &lt;code&gt;hotswappabletargetsource-bave&lt;/code&gt;, &lt;code&gt;defaultintroductionadvisor-bave&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Guava family (3 chains):&lt;/strong&gt; &lt;code&gt;functions$formapwithdefault&lt;/code&gt;, &lt;code&gt;predicates$isequaltopredicate&lt;/code&gt;, &lt;code&gt;present&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Other libraries:&lt;/strong&gt; &lt;code&gt;mutableobj-bave&lt;/code&gt; (hutool-core), &lt;code&gt;antlr4-pair-bave&lt;/code&gt; (antlr4-runtime), &lt;code&gt;clojure-proxy-hashmap&lt;/code&gt; (clojure), &lt;code&gt;jacksoninject$value-bave&lt;/code&gt; (jackson-annotations), &lt;code&gt;objectidgenerator$idkey-bave&lt;/code&gt; (jackson-databind), &lt;code&gt;tolerantmap-hashmap&lt;/code&gt; (snakeyaml), &lt;code&gt;scala-objectref-bave&lt;/code&gt; (scala-library).&lt;/p&gt;

&lt;h3&gt;
  
  
  T3 - variants
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;ewah-hashmap&lt;/code&gt; (JavaEWAH, used by Lucene/Elasticsearch) and the &lt;code&gt;federation*-hashmap&lt;/code&gt; family (4 chains, Artemis).&lt;/p&gt;

&lt;h3&gt;
  
  
  Example dispatch stack (ObjLongPair, T1, JDK 17)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HashMap.put -&amp;gt; HashMap.hash
  -&amp;gt; ObjLongPair.hashCode(ObjLongPair.java:55)
    -&amp;gt; Objects.hash -&amp;gt; Arrays.hashCode
      -&amp;gt; EqualsBean.hashCode -&amp;gt; EqualsBean.beanHashCode
        -&amp;gt; ObjectBean.toString -&amp;gt; ToStringBean.toString -&amp;gt; Method.invoke
          -&amp;gt; TemplatesImpl.defineClass -&amp;gt; payload static block
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Quick start
&lt;/h2&gt;

&lt;h3&gt;
  
  
  CLI mode (batch audit)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Install deps (Python 3.10+, JDK 11 and 17, ECJ compiler)&lt;/span&gt;
pip &lt;span class="nb"&gt;install &lt;/span&gt;chromadb  &lt;span class="c"&gt;# optional, for RAG persistence&lt;/span&gt;

&lt;span class="c"&gt;# Point at any JAR directory, get chains + PoCs&lt;/span&gt;
python3 audit_target.py &lt;span class="nt"&gt;--target&lt;/span&gt; /path/to/jars &lt;span class="nt"&gt;--name&lt;/span&gt; &lt;span class="s2"&gt;"your-product"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  TUI mode (interactive)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python3 tui.py                 &lt;span class="c"&gt;# English&lt;/span&gt;
python3 tui.py &lt;span class="nt"&gt;--lang&lt;/span&gt; zh       &lt;span class="c"&gt;# Chinese&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Key bindings: arrow keys or &lt;code&gt;j&lt;/code&gt;/&lt;code&gt;k&lt;/code&gt; to navigate chains, &lt;code&gt;Enter&lt;/code&gt; to toggle detail, &lt;code&gt;t&lt;/code&gt; to switch language, &lt;code&gt;q&lt;/code&gt; to quit.&lt;/p&gt;

&lt;h2&gt;
  
  
  Project structure
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;jgd/
  audit_target.py        # Product CLI entry point
  tui.py                 # Interactive TUI
  jgd/                   # Core agent modules (25)
    verify_agent.py      # Bridge discovery + ds adversarial audit (incremental checkpoint)
    chain_complete.py    # Chain pairing + exhaustion proof (per-item evidence)
    poc_gen.py           # Weaponized PoC generation (heq/jackson/map-dispatch tails)
    known_chains.py      # Public chain four-state determination (155-chain SQLite)
    build_chain_db.py    # Chain DB builder (155 chains, 168 version gates)
    novel_chains.py      # Novel chain auto-tiering (GLM propose + DS verify)
    matrix_agent.py      # Multi-JDK probe orchestration
    bcdisasm.py          # Pure-Python bytecode disassembler
    bridge_fix.py        # Operand-stack symbolic execution
    chroma_store.py      # RAG with corpus-scoped collections
    llm.py               # Dual-model (GLM + DeepSeek)
    scope.py             # Corpus fingerprint isolation
    conductor.py         # Acceptance-gated terminal verdict
    ...
  examples/chains.json   # All discovered chains (machine-readable)
  examples/chains.md     # Human-readable chain catalog
  tests/test_smoke.py    # Third-party reproducible test suite
  ARCHITECTURE.md        # 25-module graph + design decisions
  CHANGELOG.md           # Design decision history (R6-R52)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1. Public chain determination.&lt;/strong&gt; A 155-chain SQLite database with per-chain family, source, CVE, trigger method, sink type, JDK range, conditions, and jar version gates. Class signature matching (jar-scoped) plus JDK internal class detection, with per-jar multi-version verdicts (APPLICABLE / BLOCKED / UNVERIFIED) and dynamic assembly + fire verification using the target's own JARs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Novel chain discovery.&lt;/strong&gt; Static operand-stack symbolic execution detects receiver-bridges, argument-bridges, and Map-dispatch bridges. A real-time corpus-fingerprinted call graph plus CHA dispatch edges and JDK builtin sink seeds. Dynamic batch-parallel JVM probes across 5 carriers, with field-contract synthesis and multi-JDK coverage. Observability via marker reachability, exception stack frames, marker caller-stack, and MAPDISPATCH signals.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Adversarial auditing.&lt;/strong&gt; Dual-model proposal/verification (GLM proposes, DeepSeek verifies) with incremental checkpointing, so verify / chain / poc all resume on the same fingerprint.&lt;/p&gt;

&lt;p&gt;Repo: &lt;a href="https://github.com/lupingQAQ/JGD" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/JGD&lt;/a&gt;&lt;/p&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>java</category>
      <category>security</category>
    </item>
    <item>
      <title>Introducing ntobjmanager-mcp: stateful Windows RPC research for AI agents</title>
      <dc:creator>lupingQAQ</dc:creator>
      <pubDate>Tue, 29 Sep 2026 13:34:48 +0000</pubDate>
      <link>https://dev.to/lupingqaq/introducing-ntobjmanager-mcp-stateful-windows-rpc-research-for-ai-agents-193p</link>
      <guid>https://dev.to/lupingqaq/introducing-ntobjmanager-mcp-stateful-windows-rpc-research-for-ai-agents-193p</guid>
      <description>&lt;h1&gt;
  
  
  ntobjmanager-mcp: a stateful MCP server for Windows RPC research
&lt;/h1&gt;

&lt;p&gt;A Model Context Protocol (MCP) server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).&lt;/p&gt;

&lt;h2&gt;
  
  
  Why it exists
&lt;/h2&gt;

&lt;p&gt;Most "let an LLM drive PowerShell" setups are stateless: every tool call spawns a fresh shell, so the &lt;code&gt;RpcServer&lt;/code&gt; object you just parsed, the client you just connected, and any session variables are gone when the call returns. That breaks the workflows RPC research depends on: auth handshakes, context-handle chains, anything where step two needs the object from step one.&lt;/p&gt;

&lt;p&gt;ntobjmanager-mcp keeps a single PowerShell engine alive for the whole session and exposes it as 22 fixed tools.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two things a generic PowerShell MCP cannot do
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1. Stateful RPC connections.&lt;/strong&gt; A persistent &lt;code&gt;powershell.exe&lt;/code&gt; keeps parsed &lt;code&gt;RpcServer&lt;/code&gt; objects and connected RPC clients alive across tool calls: &lt;code&gt;rpc_connect&lt;/code&gt; once, &lt;code&gt;rpc_call&lt;/code&gt; many times. Auth handshakes, context-handle chains, and session variables survive.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. CVE methodology as fixed tools.&lt;/strong&gt; The standard hunting workflows from 2024-2026 public research ship as one-click tools instead of prompt-engineering.&lt;/p&gt;

&lt;h2&gt;
  
  
  Architecture
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;AI Agent (Claude Code / OpenCode / any MCP client)
     |  MCP (stdio, 22 tools)
     v
server.py -- snippets.py (PS templates, @@TOKEN@@ + ps_str escape)
     |
     v
ps_engine.py -- persistent powershell.exe (base64 + __MCP_DONE__)
     |            state: $RPCMCP = @{ Servers; Clients; vars }
     v
NtObjectManager / NtCoreLib  --&amp;gt;  RPC runtime (ALPC / pipe / TCP)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Tool matrix (22)
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Core stateful pipeline
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_parse(file, symbol_path?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Parse a PE for RPC servers, cache (keys &lt;code&gt;file_N&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_state()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Cached servers + live sessions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_get_interface(key)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Procedures, NDR params, context handles, strictness&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_query_endpoints(ifid?, search_binding?, find_alpc_port?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Endpoint-mapper query (local or remote)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_running_servers(pid?/service?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Live process/service enumeration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_connect(session, key, binding?, auth?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Generate + connect a client (stateful)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_methods(session)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Signatures with opnum mapping&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_call(session, method, args_json, store_as?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Reflection invoke; &lt;code&gt;{"__var__"}&lt;/code&gt; passes stored objects&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_disconnect(session)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Drop session&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  2024-2026 CVE methodology tools
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Methodology source&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_scan_context_handles(paths)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Context-handle type confusion - CVE-2025-48815 pattern (whereisk0shl 2026)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_inventory(paths?, limit?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Attack-surface inventory + EPM cross-check - MS-RPC-Fuzzer phase 1 (CVE-2025-26651)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_fuzz(session, dry_run=True)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Primitive-only default-value fuzzing with ok/denied/error classification - dry-run by default&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_find_hijackable()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Unregistered interfaces of stopped services - EPM poisoning / RPC-Racer (CVE-2025-49760 / 59200 / 59230)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_etw_unreachable(duration, trigger_script?)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Clients calling dead servers - PhantomRPC (Kaspersky 2026), admin required&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_interface_security(key)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;ALPC security descriptor / anonymous-ACE audit - MS-NRPC null session (SafeBreach / Securelist 2025)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_decode_flags(flags)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;RpcServerRegisterIf3&lt;/code&gt; flag bitmask decoding&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_format_client(key)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Export the generated C# client source (offline grep workflow)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_new_struct(session, type, store_as)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Build NDR complex types as session vars&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_alpc_squat(name, duration)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;ALPC port squat + connection capture (race validation primitive)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;rpc_accessible_tasks()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;User-startable tasks (Dark-Elevator chain material, CVE-2026-66804 pattern)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;rpc_vars&lt;/code&gt; / &lt;code&gt;rpc_clear_cache&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Session-variable and cache management (eviction cap 150)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Every tool call is appended to &lt;code&gt;output/mcp_audit.log&lt;/code&gt;, so at the end you have a full trace of what the agent actually did.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick start
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="c"&gt;# 1) Prerequisites (one-time)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;Install-Module&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;NtObjectManager&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Scope&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;CurrentUser&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Force&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;pip&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;install&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-r&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;requirements.txt&lt;/span&gt;&lt;span class="w"&gt;            &lt;/span&gt;&lt;span class="c"&gt;# mcp&amp;gt;=1.2.0 (1.x / 2.x compatible)&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="c"&gt;# 2) Verify - three suites&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;python&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;tests\smoke_test.py&lt;/span&gt;&lt;span class="w"&gt;                 &lt;/span&gt;&lt;span class="c"&gt;# 17 checks (live MCP stdio round-trip)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;python&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;tests\var_test.py&lt;/span&gt;&lt;span class="w"&gt;                   &lt;/span&gt;&lt;span class="c"&gt;# 10 checks (store_as / __var__ mechanics)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;python&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;tests\audit.py&lt;/span&gt;&lt;span class="w"&gt;                      &lt;/span&gt;&lt;span class="c"&gt;# 43 checks (edge cases, hostile paths, concurrency)&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="c"&gt;# 3) Run the server&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;python&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;server.py&lt;/span&gt;&lt;span class="w"&gt;                           &lt;/span&gt;&lt;span class="c"&gt;# stdio MCP&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Add it to an MCP client
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Claude Code:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;claude mcp add ntobjectmanager-rpc &lt;span class="nt"&gt;--&lt;/span&gt; python C:&lt;span class="se"&gt;\p&lt;/span&gt;ath&lt;span class="se"&gt;\t&lt;/span&gt;o&lt;span class="se"&gt;\n&lt;/span&gt;tobjmanager-mcp&lt;span class="se"&gt;\s&lt;/span&gt;erver.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Any MCP client (OpenCode &lt;code&gt;opencode.json&lt;/code&gt;):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcp"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"ntobjectmanager-rpc"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"local"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"python"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;path&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;to&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;ntobjmanager-mcp&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;server.py"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"enabled"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;The agent speaks MCP over stdio to &lt;code&gt;server.py&lt;/code&gt;, which compiles PowerShell snippets and hands them to a persistent &lt;code&gt;powershell.exe&lt;/code&gt; (base64-encoded, with a completion sentinel). All state lives in one PowerShell variable, &lt;code&gt;$RPCMCP = @{ Servers; Clients; vars }&lt;/code&gt;. NtObjectManager and NtCoreLib do the actual RPC work underneath, over ALPC, named pipe, or TCP.&lt;/p&gt;

&lt;p&gt;Repo and docs: &lt;a href="https://github.com/lupingQAQ/ntobjmanager-mcp" rel="noopener noreferrer"&gt;https://github.com/lupingQAQ/ntobjmanager-mcp&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>windows</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
