cobaltstrike
Open in Telegram
All about Cobalt Strike. New versions, articles and more.
Show moreThe country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
1 682
Behind the Mask: Spoofing Call Stacks Dynamically with Timers
https://www.cobaltstrike.com/blog/behind-the-mask-spoofing-call-stacks-dynamically-with-timers/
1 682
CobaltStrike toolkit to write files produced by Beacon to memory instead of disk
https://github.com/Octoberfest7/MemFiles
1 682
Developing Cobalt Strike BOFs with Visual Studio
https://blog.yaxser.io/red/developing-cobalt-strike-bofs-with-visual-studio
1 682
Detecting Cobalt Strike Fork&Run
https://blog.yaxser.io/blue/detecting-cobalt-strike-fork-and-run
1 682
CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection, persistence and more, leveraging direct syscalls (SysWhispers2) to bypass EDR/AV
https://github.com/NVISOsecurity/CobaltWhispers
1 682
Cobalt Strike BOF for quser.exe implementation using Windows API
https://github.com/netero1010/Quser-BOF
1 682
Pure-python implementation of MemoryModule technique to load a dll entirely from memory
https://github.com/naksyn/PythonMemoryModule
1 682
Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).
https://github.com/tijme/amd-ryzen-master-driver-v17-exploit
1 682
🌐SeeProxy is a Golang reverse proxy with CobaltStrike malleable profile validation.
The premise of this tool is to not open your teamserver to the world but to a single instance of SeeProxy instead.
This way every request reaching your teamserver is a legitimate C2 traffic.
DEMO: https://www.youtube.com/watch?v=iWuphwQggxk
1 682
CoffLoader
It's just un implementation of in-house CoffLoader supporting #CobaltStrike standard BOF and BSS initialized variables.
Look at the main.c file to change the BOF and its parameters. CobalStrike handles the BOF parameter in a special way, the Arg structure is here to pass parameters easier.
https://github.com/OtterHacker/CoffLoader
1 682
Aggressor script to help Red Teams identify foreign processes on a host machine
https://github.com/RomanRII/jenkins-strike
1 682
Cohab_Processes
This Aggressor script is intended to help internal #RedTeams identify suspicious or foreign processes ("Cohabitation") running in their environments.
https://github.com/Octoberfest7/Cohab_Processes
1 682
What can we and they do against CS
https://ift.tt/t9pSFbd
https://github.com/minhangxiaohui/cobaltstrikefakeup
1 682
ASRenum
Identify ASR rules, actions, and exclusion locations
https://github.com/mlcsec/ASRenum-BOF
1 682
Nighthawk Likely to Become Hackers' New Post-Exploitation Tool After Cobalt Strike
https://www.proofpoint.com/us/blog/threat-insight/nighthawk-and-coming-pentest-tool-likely-gain-threat-actor-notice
1 682
Making Cobalt Strike harder for threat actors to abuse
https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
1 682
Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike
https://blueteam.news/automating-c2-infrastructure-with-terraform-nebula-caddy-and-cobalt-strike/
1 682
An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.
https://github.com/CodeXTF2/ScreenshotBOF
1 682
Aggressor script add-in for CobaltStrike to track file uploads
https://github.com/Octoberfest7/CS_Uploads_Tracker
