appsec.fyi · Sources

ipurple.team

5 curated AppSec resources from ipurple.team across 4 topics on appsec.fyi.

ipurple.team

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-09-22.

Date Added Resource Excerpt
2026-09-22 2026Implant Encryption via the Dump Encoding LibraryDeserLibrary for abusing the Windows Error Reporting Dump Encoding Library (WerEnc.dll) to encrypt malware implants. Threat actors can leverage AES-256 encryption provided by this Microsoft-signed DLL, offering enhanced evasion capabilities against EDR systems by reducing the need for custom crypto code and obscuring analysis with keys stored in controlled infrastructure. Proof-of-concept tools like `werenc-byok.exe` and `werenc-rt.exe` demonstrate key generation, encryption of executables (e.g., `calc.bin`), and decryption of staged implants, even fetched via HTTP. Detection focuses on monitoring arbitrary processes loading `WerEnc.dll` and associated file creation events.
2026-08-25 2026Code Execution via Text Template Files | Playbook & DetectionSSTIPlaybook detailing code execution via text template files, focusing on the abuse of `TextTransform.exe`, `TextTransformCore.exe`, `t4.exe`, and `MSBuild.exe`. This technique allows threat actors to embed C# or Visual Basic code within `.tt` files, leading to execution in trusted processes or supply chain compromises. The document examines undocumented methods of using `t4.exe` and `MSBuild.exe` for arbitrary code execution, providing detailed examples and detection strategies.
2026-08-05 2026Code Execution via Provisioning PackagesRCELibrary for abusing Windows Provisioning Packages (.ppkg) to execute arbitrary code. Threat actors can disguise malicious payloads within these containers, which are used by administrators for device configuration. The library leverages the Windows Imaging and Configuration Designer (ICD.exe) to create malicious packages, with extracted commands residing in `customizations.xml` and executable via `provtool.exe`. Detection methods include monitoring the Microsoft-Windows-Provisioning-Diagnostics-Provider event log (event ID 20 for package application, event ID 10 for associated file information) and auditing file system access to `C:\ProgramData\Microsoft\Provisioning` and temporary staging directories.
2026-07-14 2026Persistence via Fake AMSI Provider | Playbook & Detection StrategiesRCELibrary that demonstrates persistence via a fake AMSI provider. This technique abuses the Antimalware Scan Interface (AMSI) by registering a malicious provider that can execute arbitrary code when specific trigger strings are detected in PowerShell content. The provided C++ code implements a sample AMSI provider that allows threat actors with elevated permissions to achieve persistence by bypassing security scans.
2024-09-11 2024Browser Stored CredentialsSecretsLibrary for harvesting credentials from browsers, focusing on T1555.003. It details how modern browsers like Chrome and Edge utilize DPAPI for encrypting user credentials and outlines the file locations for storing this sensitive data. The library discusses tools like Lazagne, SharpChrome, and DonPAPI, emphasizing that detection should focus on the behavior of processes accessing credential files and the CryptUnprotectData API, rather than signature-based methods. It provides a playbook for purple teams to emulate this technique and assess SOC detection capabilities.