Skip to content
View NomanNasirMinhas's full-sized avatar

Highlights

  • Pro

Block or report NomanNasirMinhas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NomanNasirMinhas/README.md
SHELLDONE

Break the abstraction. Emulate the adversary. Harden what's left. Kernel-space when it has to be Β· forests when they let me in.


boot sequence

noman@psiberus-lab:~$ ./whoami --verbose
[*] resolving operator identity ................ OK
[*] loading evasion + injection modules ........ OK
[*] mounting AD attack + kernel toolkits ....... OK

uid=0(root) gid=0(root) groups=0(root),1337(red-team),31337(elite)
Linux psiberus-lab 6.x.x-hardened #1 SMP PREEMPT x86_64 GNU/Linux

OPERATOR  : Noman Nasir Minhas          ALIAS : Sheldon / malicious_dll
ROLE      : Security Engineer β€” Offensive Ops & Adversary Emulation
ORG       : Cytomate Solutions & Services β€” Doha, Qatar
FOUNDER   : Psiberus LLC β€” Autonomous Adversary Simulation Platform
EDUCATION : MS Cybersecurity β€” Air University Β· IEEE Published
STATUS    : ACTIVE β€” CRTO βœ”  CRTL βœ”  [Red Team Operator + Lead]

TryHackMe

☠️ THREAT ACTOR PROFILE

╔═══════════════════════════════════════════════════════════════╗
β•‘ CLASSIFICATION: [TOP SECRET // OFFSEC // RED CELL]            β•‘
╠═══════════════════════════════════════════════════════════════╣
β•‘ OPERATOR  : Noman Nasir Minhas                                β•‘
β•‘ HANDLE    : Sheldon / malicious_dll                           β•‘
β•‘ MISSION   : Break. Emulate. Detect. Harden. Repeat.           β•‘
β•‘ THEATER   : Windows Internals Β· AD Β· EDR Β· Post-Exploitation  β•‘
β•‘ WEAPONS   : Rust Β· Go Β· C/C++ Β· C# Β· Python Β· ASM             β•‘
β•‘ LAB ENV   : VMware/Hyper-V Β· AD Forest Β· ELK Β· MDE Β· Sysmon   β•‘
β•‘ INTEL ORG : Cytomate Solutions β€” Adversary Emulation Division β•‘
β•‘ FOUNDER   : Psiberus LLC β€” Autonomous Adversary Sim Platform  β•‘
β•‘ CERTS     : CRTO (Operator) + CRTL (Lead) β€” Zero-Point Sec    β•‘
β•‘ OFF-HOURS : quantum computing + physics β€” self-study, for fun β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

Most operators stop at the exploit. I keep going β€” down into kernel objects, callback tables, and the telemetry that's supposed to catch me. Break it, emulate it, then help the blue side see it coming.


🎯 CURRENT OPS

noman@psiberus-lab:~$ cat /var/log/active_ops.log
[+] ADVERSARY SIMULATION  β€” Full-scope red team engagements @ Cytomate.
                            MITRE ATT&CK-mapped campaigns, purple team
                            pipelines, ASL-driven scenario automation
[+] KERNEL DRIVERS DEV    β€” Windows kernel driver research in Rust (WDK).
                            EDR/AV internals, DKOM, callback manipulation
                            minifilter drivers, object/handle hooking
[+] AD SECURITY RESEARCH  β€” Cross-domain / forest trust attack chains,
                            Kerberos delegation abuse, ExtraSids golden
                            ticket forgery, DCSync, BloodHound pathing
[+] POST-QUANTUM CRYPTO   β€” Kyber-768 / Dilithium3 protocol integration,
                            quantum-safe secure channel design + PQC
                            migration tooling for offensive/defensive use
[+] EDR EVASION R&D       β€” AMSI heap corruption (HAMSICONTEXT), ETW
                            patching, patchless syscall techniques, DLL
                            call tracing via Frida, hook evasion research
[+] PSIBERUS PLATFORM     β€” Rust+Go+Tauri autonomous adversary sim suite.
                            MQTT/RabbitMQ C2 backend, ELK/MDE telemetry

πŸ› οΈ ARSENAL β€” TOOLING & TRADECRAFT

βš™οΈ Offensive Tooling (click to expand)

Windows Evasion & Injection

  • AMSI Bypass: Heap corruption via HAMSICONTEXT, patchless ntdll-level techniques, ETW patching
  • DLL Unhooking: Section remapping, fresh ntdll load, manual syscall resolution
  • Process Injection: Fork-chain injection (Go), APC injection, thread hijack, shellcode fluctuation (Rust)
  • Module Stomping: dinvoke_rs-powered stomping with in-memory PE manipulation
  • Loaders: AES-256-CBC/CTR shellcode encryption/decryption; Zig-based loader with runtime decryption
  • Frida Tracing: Cross-DLL call chain visibility with full forwarding chain resolution

Active Directory Tradecraft

  • Kerberoasting / ASREPRoasting via Impacket / Rubeus
  • Golden Ticket Forgery: ExtraSids field manipulation for cross-domain trust attacks (child β†’ parent)
  • DCSync / SecretsDump: Credential harvesting from domain controllers
  • BloodHound: Graph-based attack path enumeration
  • Forest Trust Pivoting: Inter-forest lateral movement (CONTOSO ↔ ENCLAVE)
  • Constrained Delegation Abuse: S4U2self / S4U2proxy exploitation

Network & Protocol Attacks

  • ARP Poisoning (ARP-Puker): Gratuitous ARP MITM at Layer 2
  • NTLMv1/v2 Capture: Inveigh / Responder relay chains
  • WPAD / Proxy Abuse: Transparent traffic interception
  • TLS Fingerprinting: JA3/JA3S analysis via Zeek
πŸ¦€ Languages & Runtimes
Language     | Proficiency  | Primary Use
─────────────────────────────────────────────────────────────
Rust         | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ | Implants, drivers, ARP tooling, C2 agents
Go           | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ | Microservices, C2 runners, network tools, loaders
C / C++      | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ | Malware internals, WinAPI, kernel research
C#           | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ | .NET post-exploitation, Cobalt Strike BOFs
Python       | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ | Automation, Impacket, tooling scripts
x86/x64 ASM  | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘ | Shellcode, syscall stubs, manual trampolines
PowerShell   | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ | AD recon, living-off-the-land
Zig          | β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ | Shellcode loaders, cross-compilation experiments
πŸ”§ Tools & Frameworks
Category Tools
C2 Frameworks Cobalt Strike, custom MQTT/RabbitMQ C2 (Psiberus)
RE / Analysis IDA Pro, Ghidra, x64dbg, Frida, Volatility
Network Wireshark, Zeek, Suricata, Nmap, Inveigh, Responder
AD Attacks BloodHound, Impacket, CrackMapExec, Mimikatz, Rubeus
Web Burp Suite, sqlmap, ffuf
Vuln Scanning OpenSCAP, Lynis, CVE Binary Tool (air-gapped)
EDR/SIEM MDE, Sysmon, ELK Stack, custom ETW consumers
Crypto Kyber/Dilithium (PQC), AES-256 CTR/CBC, C2PA

πŸ”¬ RESEARCH DOMAINS

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DOMAIN                  CURRENT FOCUS                         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Windows Evasion         AMSI/ETW internals, heap corruption,  β”‚
β”‚                         patchless bypasses, call-stack spoof  β”‚
β”‚ Active Directory        Cross-domain / forest trust attacks,  β”‚
β”‚                         ExtraSids golden ticket, Kerberos     β”‚
β”‚ EDR Research            Telemetry blind spots, hook evasion,  β”‚
β”‚                         MDE signal analysis, DLL tracing      β”‚
β”‚ Post-Quantum Crypto     Kyber-768, Dilithium3, secure-channel β”‚
β”‚                         design, PQC migration tooling         β”‚
β”‚ Adversary Emulation     MITRE ATT&CK mapping, ASL framework,  β”‚
β”‚                         automated purple-team pipelines       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“¦ REPOSITORY INDEX

Repo Lang TTP / Purpose
Offensive-Rust πŸ¦€ Rust C2 server Β· local/remote shellcode injection Β· WinAPI bindings
Offensive-Go 🐹 Go GoShark (packet capture UI) · NetworkMonitor passive listener
Rust-Driver-Clone πŸ¦€ Rust Windows kernel driver (WDK) β€” EDR/AV internals research
ARP-Puker πŸ¦€ Rust Gratuitous ARP poisoning Β· Layer-2 MITM packet interception
binary-to-shellcode πŸ”§ Multi PE β†’ PIC shellcode conversion with encryption support
CPP-Utils βš™οΈ C++ Utility library for malware/offensive tooling (MSVC)
Pentesting-Notes πŸ“ β€” AD attack mindmaps Β· pentest cheatsheets Β· CherryTree notes
Qiskit-Quantum 🐍 Python Qiskit notebooks β€” quantum computing (personal study)

Private / WIP: Psiberus agent (Rust) Β· Zig shellcode loader Β· Go fork-chain injector Β· Rust fluctuation implant Β· ASL JSON generator Β· sandbox/VM detection toolkit


πŸ—οΈ PSIBERUS β€” AUTONOMOUS ADVERSARY SIM PLATFORM

psiberus@lab:~$ cat /opt/psiberus/README
PSIBERUS β€” Autonomous AI-Driven Penetration Testing Platform
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
STACK:
  Agent       β†’ Rust (evasion-first, modular payload)
  Operator UI β†’ Tauri + Svelte (desktop)
  C2 Backend  β†’ Go microservices, MQTT/RabbitMQ transport
  Telemetry   β†’ ELK + MDE + Sysmon correlation engine
  Emulation   β†’ MITRE ATT&CK mapped, ASL-native scenario engine
STATUS: [PRIVATE ALPHA] β€” Founder: Psiberus LLC, Doha QA

πŸ“Š OPERATIONAL STATS

GitHub Stats Top Languages Streak

trophy


✍️ INTEL DUMP β€” WRITING & TALKS

  • πŸ“‘ Medium @malicious-dll β€” Loader design, ETW/AMSI internals, token manipulation, memory forensics, AD attack/defense
  • πŸ”¬ IEEE Research β€” Published peer-reviewed offensive security research
  • 🧠 Instagram β€” Casual science communication on the side (physics, quantum, space) β€” a hobby, not a day job

πŸ§ͺ CERTIFICATIONS & LABS



πŸ“‘ ESTABLISH CONNECTION

noman@psiberus-lab:~$ netstat --contact
PROTOCOL   ENDPOINT                               STATUS
EMAIL    β†’ contact.nomanminhas@gmail.com         OPEN
TWITTER  β†’ @malicious_dll                        LISTENING
LINKEDIN β†’ /in/noman-nasir-minhas                AUTHENTICATED
MEDIUM   β†’ @malicious-dll                        PUBLISHING
GITHUB   β†’ /NomanNasirMinhas                     PUBLIC
TOPICS: GoLang Β· Rust Β· C2 Dev Β· EDR Evasion Β· AD Attacks
        Post-Quantum Crypto Β· Exploit Dev Β· Red/Purple Ops


DEF IN SILENCE

"The best defense is understanding how the offense thinks."

πŸ¦‚ Malware Researcher Β· Exploit Developer Β· Kernel Tinkerer Β· Red/Purple Team Lead

All offensive research conducted in controlled lab environments for ethical R&D and defense purposes.

Popular repositories Loading

  1. File-Blinder File-Blinder Public

    Windows process instrumentation toolkit for authorized security research, file-access manipulation, DLL search-order analysis, application resilience testing, and detection engineering.

    Rust 7

  2. PPLease PPLease Public

    Python 5 2

  3. Orca Orca Public

    Go 5 3

  4. Offensive-Rust Offensive-Rust Public

    Rust 4

  5. nanga nanga Public

    Windows SSDT hook framework for full-spectrum syscall, file, registry, and network monitoring. Built for malware analysis and offensive security research.

    C 4

  6. Code-With-Imran-Khan-VS-Code-Extentsion Code-With-Imran-Khan-VS-Code-Extentsion Public

    TypeScript 2