en
Feedback
cobaltstrike

cobaltstrike

Open in Telegram

All about Cobalt Strike. New versions, articles and more.

Show more
The country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Cobalt Strike Aggressor scripts https://github.com/dinimus/Cobalt_Strike_scripts

DNS Tunneling using powershell to download and execute a beacon. Works in CLM. https://github.com/Octoberfest7/DNS_Tunneling

CoffeeLdr A Beacon Object File Loader https://github.com/Cracked5pider/CoffeeLdr

Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/

CobaltStrike Malleable PE https://tttang.com/archive/1662/

A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed. https://github.com/Cracked5pider/KaynStrike

A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities. https://github.com/m3rcer/Chisel-Strike

PersistBOF A tool to help automate common persistence mechanisms. Currently supports Print Monitor (SYSTEM), Time Provider (Network Service), Start folder shortcut hijacking (User), and Junction Folder (User) https://github.com/IcebreakerSecurity/PersistBOF

This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently, it supports RBCD, Constrained, Constrained w/Protocol Transition, and Unconstrained Delegation checks. https://github.com/IcebreakerSecurity/DelegationBOF

ElevatedEvents EventViewer UAC bypass via .NET Deserialization discovered by @OrangeTsai made into a Reflective DLL to use with Cobalt Strike. https://github.com/jsecu/ElevatedEvents

Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities. https://github.com/boku7/BokuLoader

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking. https://github.com/netero1010/RDPHijack-BOF

photo content

Why does the new Trigun design look like the Cobalt Strike mascot? 😳
Why does the new Trigun design look like the Cobalt Strike mascot? 😳

Bulk Analysis of Cobalt Strike's Beacon Configurations https://www.archcloudlabs.com/projects/bulk-cs-analysis/
Bulk Analysis of Cobalt Strike's Beacon Configurations https://www.archcloudlabs.com/projects/bulk-cs-analysis/

Pulling down a live Cobalt Strike beacon from a c2 server for analysis! https://blog.spookysec.net/cs-beacon-analysis/

If you have ever wanted to detect a Cobalt Strike beacon installed through PowerShell, watch this video. I will also show you how to reverse the log to find the C2 server with CyberChef. (https://twitter.com/BriPwn) https://www.youtube.com/watch?v=5GUx_6xWoeI

Update to nanodump! You can now force WerFault.exe to dump LSASS for you. Thanks to @asaf_gilboa for the original research. https://github.com/helpsystems/nanodump