{"id":51410510,"url":"https://github.com/momenbasel/quiet-operator","last_synced_at":"2026-07-04T14:32:27.358Z","repository":{"id":361643093,"uuid":"1255238256","full_name":"momenbasel/quiet-operator","owner":"momenbasel","description":"A purple-team field manual for staying stealthy on the host and on the wire. Linux-first. Every offensive page paired with detection telemetry.","archived":false,"fork":false,"pushed_at":"2026-05-31T15:33:14.000Z","size":255,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-31T17:17:27.603Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"CSS","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/momenbasel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-31T15:26:33.000Z","updated_at":"2026-05-31T16:19:56.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/momenbasel/quiet-operator","commit_stats":null,"previous_names":["momenbasel/quiet-operator"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/momenbasel/quiet-operator","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/momenbasel%2Fquiet-operator","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/momenbasel%2Fquiet-operator/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/momenbasel%2Fquiet-operator/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/momenbasel%2Fquiet-operator/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/momenbasel","download_url":"https://codeload.github.com/momenbasel/quiet-operator/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/momenbasel%2Fquiet-operator/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35125718,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-04T02:00:05.987Z","response_time":113,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-07-04T14:32:26.876Z","updated_at":"2026-07-04T14:32:27.340Z","avatar_url":"https://github.com/momenbasel.png","language":"CSS","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n# Quiet Operator\n\n**A purple-team field manual for staying stealthy on the host and on the wire.**\n\nTradecraft for *authorized* red team operations, paired page-for-page with the\n**detection telemetry** defenders use to catch it.\n\n\u003cbr\u003e\n\n![Focus](https://img.shields.io/badge/focus-OPSEC%20%26%20stealth-111111)\n![Linux first](https://img.shields.io/badge/Linux-first%20%26%20deepest-1793D1?logo=linux\u0026logoColor=white)\n![Then Windows](https://img.shields.io/badge/Windows-covered-0078D6?logo=windows\u0026logoColor=white)\n![Data transfer](https://img.shields.io/badge/data%20transfer-exfil%20%2B%20telemetry-7B42BC)\n![Approach](https://img.shields.io/badge/approach-purple%20team-8A2BE2)\n![ATT\u0026CK](https://img.shields.io/badge/mapped%20to-MITRE%20ATT%26CK-E02401)\n![License](https://img.shields.io/badge/license-MIT-2EA043)\n![Use](https://img.shields.io/badge/use-authorized%20engagements%20only-critical)\n![HTB Writeups](https://img.shields.io/badge/HTB%20writeups-momenbasel.github.io-9FEF00?logo=hackthebox\u0026logoColor=black)\n\n\u003cbr\u003e\n\n*Linux first. Then data transfer / exfiltration. Then Windows. Then C2 infrastructure.*\n*Every offensive page ends with the artifacts it leaves behind.*\n\n\u003c/div\u003e\n\n---\n\n\u003e [!CAUTION]\n\u003e **Authorized engagements only.** Read [`DISCLAIMER.md`](DISCLAIMER.md) before anything\n\u003e else. Use this material only with signed scope (ROE/SOW), in your own lab, or in a CTF.\n\u003e Unauthorized access, interception, and exfiltration are crimes. Every offensive page\n\u003e here ships with a **Detection \u0026 telemetry** section written *for the blue team* - that\n\u003e pairing is the point.\n\n---\n\n## Table of contents\n\n- [The thesis: stealth is telemetry management](#the-thesis-stealth-is-telemetry-management)\n- [Who this is for](#who-this-is-for)\n- [Visual overview](#visual-overview)\n- [Quick start](#quick-start)\n- [The map](#the-map)\n  - [0. Foundations](#0-foundations--read-first)\n  - [1. Linux (deepest)](#1-linux-deepest)\n  - [2. Data transfer / exfiltration](#2-data-transfer--exfiltration)\n  - [3. Windows](#3-windows)\n  - [4. C2 infrastructure OPSEC](#4-c2-infrastructure-opsec)\n  - [5. Defender's cross-mapping](#5-defenders-cross-mapping)\n  - [References](#references)\n- [The artifact-cost idea in one table](#the-artifact-cost-idea-in-one-table)\n- [The base64 lesson](#the-base64-lesson-encoding-is-not-hiding)\n- [How the repo is structured](#how-the-repo-is-structured)\n- [Contributing](#contributing)\n- [License](#license)\n\n---\n\n## The thesis: stealth is telemetry management\n\nMost \"evasion\" notes teach you to *do* a thing without teaching you what the thing\n*leaves behind*. An operator who does not know which log line, syscall, or event ID\ntheir command produced is not stealthy - they are lucky.\n\nThis manual treats stealth as **telemetry management**. Every action has a cost paid in\nartifacts: a disk write, a spawned process, an outbound connection, an auth event, a log\nline. Good tradecraft is choosing the **cheapest path in artifacts** that still gets the\njob done - and knowing exactly who is collecting each one. Defenders get the same pages\nand learn precisely where to look. Offense and defense ship together here on purpose.\n\nThree rules the whole repo is built on:\n\n1. **Avoid generating the artifact - do not try to delete it.** In a world of central\n   SIEM and log forwarding, local deletion is near-useless and is itself a screaming IOC.\n2. **Native and expected beats novel and dropped** - but command-line and behavioral\n   telemetry still capture you. Living off the land defeats AV signatures, not EDR lineage.\n3. **Regularity and volume are the meta-tells.** Fixed intervals and fixed sizes get you\n   caught long after the payload was \"undetectable.\" Encoding does not fix this; it usually\n   makes it worse.\n\n## Who this is for\n\n| You are... | Start here | You get |\n|---|---|---|\n| A **red team operator** on an authorized engagement | [Foundations](docs/00-foundations/operator-opsec-model.md) then your target OS | The quiet variant of each technique and your blast radius in artifacts |\n| A **blue teamer / detection engineer** | [`detection-mapping/`](docs/detection-mapping/blue-team-view-and-attack-mapping.md) | The exact log source, event ID, and hunt query for each technique |\n| A **purple team** running a joint exercise | [Threat model \u0026 telemetry](docs/00-foundations/threat-model-and-telemetry.md) | A shared vocabulary for \"what does this look like to the SOC\" |\n\n## Visual overview\n\nTwo charts capture the whole thesis. The full set is in [`docs/diagrams.md`](docs/diagrams.md):\nthe operator decision loop, the exfil channel decision tree, the base64 decode-and-execute\ntelemetry data-flow, a noise-vs-value technique quadrant, the defender telemetry mind-map,\nand the kill chain annotated with the loudest signal at each stage.\n\n**Operator decision loop** - run this before every action. Spend artifacts deliberately, not by accident.\n\n```mermaid\nflowchart TD\n    A[Action under consideration] --\u003e B{What artifacts does it produce?}\n    B --\u003e C[Enumerate: disk write, new process, outbound conn, auth event, log line]\n    C --\u003e D{Who collects each artifact?}\n    D --\u003e E[Host EDR / auditd / eBPF]\n    D --\u003e F[Network: NetFlow / Zeek / IDS / proxy]\n    D --\u003e G[Identity / SIEM / UEBA / cloud audit]\n    E --\u003e H{Is there a quieter primitive?}\n    F --\u003e H\n    G --\u003e H\n    H --\u003e|Yes| I[Switch to the cheaper-in-artifacts path]\n    I --\u003e J{Does the quieter path still meet the objective?}\n    J --\u003e|No| K[Reconsider objective or accept the louder path knowingly]\n    J --\u003e|Yes| L{Worth the trace it still leaves?}\n    H --\u003e|No| L\n    K --\u003e L\n    L --\u003e|No| M[Do not act. Find another route]\n    L --\u003e|Yes| N[Act. Log expected artifacts for deconfliction]\n    N --\u003e O[Record what you generated for the purple-team report]\n    M --\u003e A\n```\n\n**Base64 decode-and-execute data flow** - encoding raises signal, it does not lower it. Every stage is a place a defender already watches.\n\n```mermaid\nflowchart LR\n    A[Operator types curl pipe base64 -d pipe sh] --\u003e B[Shell history file]\n    A --\u003e C[Kernel execve syscall]\n    C --\u003e D[auditd execve and proctitle records]\n    C --\u003e E[eBPF and EDR process tree]\n    A --\u003e F[Outbound HTTPS fetch of payload]\n    F --\u003e G[NetFlow and conntrack record]\n    F --\u003e H[IDS content match on the wire]\n    F --\u003e I[Proxy and DLP charset and entropy check]\n    E --\u003e J[Lineage tell: bash spawns curl base64 sh]\n    D --\u003e K[Full argv captured: base64 -d visible verbatim]\n    H --\u003e L[Regex on A-Za-z0-9+/ run with padding]\n    I --\u003e L\n    B --\u003e M[DFIR collection of plaintext one-liner]\n    J --\u003e N[SIEM correlation and alert]\n    K --\u003e N\n    L --\u003e N\n    G --\u003e N\n    M --\u003e N\n    N --\u003e O[Decode-and-execute behavior flagged]\n```\n\n## Quick start\n\n```text\n1. Read DISCLAIMER.md and confirm you have written authorization in scope.\n2. Read docs/00-foundations/ - the OPSEC model, ROE, and the defender threat model.\n3. Open the page for your task. Read it bottom-up:\n   - \"Detection \u0026 telemetry\" first  -\u003e know what you are about to generate.\n   - \"OPSEC notes\"                   -\u003e pick the quiet variant.\n   - \"Technique\"                     -\u003e the how.\n4. Cross-check docs/detection-mapping/ to see how a SOC would catch you.\n```\n\n## The map\n\n### 0. Foundations - read first\n| Page | Covers |\n|------|--------|\n| [Operator OPSEC model](docs/00-foundations/operator-opsec-model.md) | Artifact budgeting, the noise/value trade, kill-chain discipline |\n| [Authorization \u0026 ROE](docs/00-foundations/authorization-and-roe.md) | Scope, deconfliction, data handling, stop conditions |\n| [Threat model \u0026 telemetry](docs/00-foundations/threat-model-and-telemetry.md) | What the modern defender actually collects: EDR, eBPF, Sysmon, SIEM |\n\n### 1. Linux (deepest)\n| Page | Covers |\n|------|--------|\n| [Host triage \u0026 situational awareness](docs/linux/01-host-triage-and-situational-awareness.md) | Reading the environment quietly before you touch it |\n| [Process stealth \u0026 masquerading](docs/linux/02-process-stealth-and-masquerading.md) | argv/comm spoofing, memfd, fileless exec, hiding from `ps` |\n| [Persistence stealth](docs/linux/03-persistence-stealth.md) | systemd, cron, udev, PAM, LD_PRELOAD - and their footprints |\n| [Log \u0026 anti-forensics](docs/linux/04-log-and-anti-forensics.md) | auth.log, utmp/wtmp/btmp, journald, history, timestomping |\n| [Living off the land](docs/linux/05-living-off-the-land.md) | GTFOBins, native interpreters, avoiding dropped binaries |\n| [Network stealth \u0026 tunneling](docs/linux/06-network-stealth-and-tunneling.md) | Egress selection, SSH/proxy tunnels, traffic blending, timing |\n| [EDR \u0026 kernel telemetry evasion](docs/linux/07-edr-and-kernel-telemetry-evasion.md) | auditd, eBPF, ptrace, syscall awareness, what is and is not hookable |\n| [Credential access \u0026 lateral movement](docs/linux/08-credential-access-and-lateral-movement.md) | SSH agent/keys, quiet pivoting, avoiding lockouts and alerts |\n\n### 2. Data transfer / exfiltration\n| Page | Covers |\n|------|--------|\n| [Exfil principles \u0026 staging](docs/data-transfer/01-exfil-principles-and-staging.md) | What to take, chunking, throttling, when to move |\n| [Encoding, compression \u0026 encryption](docs/data-transfer/02-encoding-compression-encryption.md) | **base64 / encoding telemetry**, compress-then-encrypt, splitting |\n| [DNS tunneling](docs/data-transfer/03-dns-tunneling.md) | Low-and-slow DNS exfil and how resolvers log it |\n| [HTTPS \u0026 cloud exfil](docs/data-transfer/04-https-and-cloud-exfil.md) | Blending into SaaS/cloud egress, webhooks, object storage |\n| [Covert channels](docs/data-transfer/05-covert-channels.md) | ICMP, timing channels, steganography |\n| [Out-of-band \u0026 throttling](docs/data-transfer/06-out-of-band-and-throttling.md) | Rate shaping, jitter, off-hours, alternate media |\n\n### 3. Windows\n| Page | Covers |\n|------|--------|\n| [Process stealth](docs/windows/01-process-stealth.md) | PPID spoofing, masquerading, command-line logging awareness |\n| [Persistence stealth](docs/windows/02-persistence-stealth.md) | Run keys, tasks, services, WMI, COM - with their event trails |\n| [Log \u0026 anti-forensics](docs/windows/03-log-and-anti-forensics.md) | Security/PowerShell/Sysmon logs, ETW, what clearing costs you |\n| [LOLBAS \u0026 execution](docs/windows/04-lolbas-and-execution.md) | Signed-binary proxy execution and the telemetry it still emits |\n| [EDR evasion: AMSI \u0026 ETW](docs/windows/05-edr-evasion-amsi-etw.md) | AMSI/ETW concepts, script-block logging, defensive blind spots |\n\n### 4. C2 infrastructure OPSEC\n| Page | Covers |\n|------|--------|\n| [Redirectors \u0026 domain fronting](docs/c2-infrastructure/01-redirectors-and-domain-fronting.md) | Hiding the team server, categorization, TLS |\n| [Malleable profiles \u0026 jitter](docs/c2-infrastructure/02-malleable-profiles-and-jitter.md) | Shaping beacon traffic: sleep, jitter, indicators |\n| [Infrastructure segregation \u0026 OPSEC](docs/c2-infrastructure/03-infrastructure-segregation-and-opsec.md) | Tiering, burn procedures, attribution hygiene |\n\n### 5. Defender's cross-mapping\n| Page | Covers |\n|------|--------|\n| [Blue-team view \u0026 ATT\u0026CK mapping](docs/detection-mapping/blue-team-view-and-attack-mapping.md) | Every technique here, mapped to detections |\n| [base64 \u0026 encoding telemetry](docs/detection-mapping/base64-and-encoding-telemetry.md) | **Exactly what is logged when you encode/decode to move data** |\n\n### References\n| Page | Covers |\n|------|--------|\n| [Diagrams](docs/diagrams.md) | The full set of Mermaid charts |\n| [Tooling index](docs/references/tooling-index.md) | Native + open-source tooling, with OPSEC ratings |\n| [MITRE ATT\u0026CK crosswalk](docs/references/mitre-attack-crosswalk.md) | Technique-ID table for the whole repo |\n\n## The artifact-cost idea in one table\n\nA condensed preview of the model. The full reasoning is in\n[the OPSEC model page](docs/00-foundations/operator-opsec-model.md).\n\n| Action | Typical artifacts | Who collects it |\n|---|---|---|\n| Run a command | `auditd` execve, shell history, EDR process event (full argv) | Host EDR, auditd, SIEM |\n| Spawn a shell from a utility | Anomalous parent-child lineage | EDR, Sysmon/Falco |\n| New outbound connection | NetFlow/IPFIX record, conntrack, possibly DNS + proxy log | NSM, firewall, proxy |\n| `sudo -l` / failed auth | `auth.log`/`secure`, btmp, UEBA signal | SIEM, IdP |\n| Read `id_rsa` / `credentials` | File-access event (auditd watch / EDR) | EDR, FIM |\n| New persistence (cron/systemd/Run key/task) | File create + service/task/registry event | FIM, Sysmon, autoruns |\n| `base64 -d \\| sh` | Process tree + decoded content in logs + on-wire pattern | EDR, IDS, DLP |\n| Clear a log | The clear event itself (Linux config-change / Win 1102) | SIEM (already forwarded) |\n| Large/odd outbound volume | NetFlow volume anomaly, DLP content match | NSM, DLP, UEBA |\n\n## The base64 lesson: encoding is not hiding\n\nOperators reach for `base64` constantly - to move binary over text channels, to fit data\ninto DNS labels or JSON, to copy-paste blobs. It is worth being blunt about what it costs,\nbecause this repo treats it as a worked example of the whole thesis:\n\n- **It is encoding, not encryption.** Any analyst decodes it instantly. It hides nothing.\n- **It raises signal, it does not lower it.** It inflates size ~33%, produces a\n  recognizable `[A-Za-z0-9+/]+=*` charset, and bumps string entropy - all of which DLP,\n  IDS, and entropy analytics key on.\n- **The command line is logged in full.** `cat secrets.tar | base64 | curl ...` records a\n  `base64` child process with its parent and arguments in `auditd` execve and EDR. Shell\n  history keeps it too.\n- **`... | base64 -d | sh` is one of the most heavily signatured patterns in existence.**\n  Sigma, Falco, and EDR all flag decode-and-execute. On Windows, `certutil -decode` and\n  PowerShell `-EncodedCommand` are the direct equivalents - and Script Block Logging\n  (event **4104**) records the *decoded* content.\n- **On the wire, long base64 strings** in HTTP bodies, URLs, headers, cookies, and DNS\n  labels are matched by Suricata/Snort content rules and proxy DLP.\n\nThe genuinely quieter move is real encryption to opaque bytes sent *inside an already-\nencrypted, expected channel* - but even then the entropy, volume, and TLS metadata tells\nremain. Full treatment:\n[**data-transfer/02**](docs/data-transfer/02-encoding-compression-encryption.md) and the\ndedicated deep-dive\n[**detection-mapping/base64-and-encoding-telemetry**](docs/detection-mapping/base64-and-encoding-telemetry.md).\n\n## How the repo is structured\n\n```text\nquiet-operator/\n├── README.md                     \u003c- you are here\n├── DISCLAIMER.md                 \u003c- authorized-use terms (read first)\n├── CONTRIBUTING.md               \u003c- the page contract every doc follows\n├── LICENSE                       \u003c- MIT\n└── docs/\n    ├── 00-foundations/           \u003c- OPSEC model, ROE, defender threat model\n    ├── linux/                    \u003c- 8 pages, deepest coverage\n    ├── data-transfer/            \u003c- 6 pages, exfil tradecraft + telemetry\n    ├── windows/                  \u003c- 5 pages\n    ├── c2-infrastructure/        \u003c- 3 pages, infra OPSEC\n    ├── detection-mapping/        \u003c- blue-team index + base64 deep-dive\n    ├── references/               \u003c- tooling index + ATT\u0026CK crosswalk\n    └── diagrams.md               \u003c- all Mermaid charts\n```\n\nEvery page follows the same contract (see [`CONTRIBUTING.md`](CONTRIBUTING.md)):\n**What \u0026 why -\u003e Technique -\u003e OPSEC notes -\u003e Detection \u0026 telemetry -\u003e MITRE ATT\u0026CK -\u003e\nReferences.** A page with a weak detection section does not get merged.\n\n## Want to practice this on real boxes?\n\nApply these techniques against HackTheBox machines - a controlled, legal environment with\nreal operating systems and real defenses.\n\n**[HTB writeups by the author - momenbasel.github.io/htb-writeups](https://momenbasel.github.io/htb-writeups/)**\n\nEach writeup documents the full attack path including the telemetry the technique would have\ngenerated - a practical companion to the theory in this repo.\n\n## Contributing\n\nPRs welcome from operators and defenders. Keep examples to lab/RFC-5737 documentation IPs\nand `example.com` - no live targets, no real loot. Pair every offensive note with its\ndetection. See [`CONTRIBUTING.md`](CONTRIBUTING.md).\n\n## License\n\n[MIT](LICENSE). Educational and authorized-testing use only. See [`DISCLAIMER.md`](DISCLAIMER.md).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmomenbasel%2Fquiet-operator","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmomenbasel%2Fquiet-operator","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmomenbasel%2Fquiet-operator/lists"}