cobaltstrike
Open in Telegram
All about Cobalt Strike. New versions, articles and more.
Show moreThe country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
1 682
DNS Tunneling using powershell to download and execute a beacon. Works in CLM.
https://github.com/Octoberfest7/DNS_Tunneling
1 682
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/
1 682
A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.
https://github.com/Cracked5pider/KaynStrike
1 682
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
https://github.com/m3rcer/Chisel-Strike
1 682
PersistBOF
A tool to help automate common persistence mechanisms. Currently supports Print Monitor (SYSTEM), Time Provider (Network Service), Start folder shortcut hijacking (User), and Junction Folder (User)
https://github.com/IcebreakerSecurity/PersistBOF
1 682
This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently, it supports RBCD, Constrained, Constrained w/Protocol Transition, and Unconstrained Delegation checks.
https://github.com/IcebreakerSecurity/DelegationBOF
1 682
ElevatedEvents
EventViewer UAC bypass via .NET Deserialization discovered by @OrangeTsai made into a Reflective DLL to use with Cobalt Strike.
https://github.com/jsecu/ElevatedEvents
1 682
Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities.
https://github.com/boku7/BokuLoader
1 682
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.
https://github.com/netero1010/RDPHijack-BOF
1 682
Koh: The Token Stealer
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
https://github.com/GhostPack/Koh
1 682
Ransomware, hacking groups move from Cobalt Strike to Brute Ratel
https://www.bleepingcomputer.com/news/security/ransomware-hacking-groups-move-from-cobalt-strike-to-brute-ratel/
1 682
Bulk Analysis of Cobalt Strike's Beacon Configurations
https://www.archcloudlabs.com/projects/bulk-cs-analysis/
1 682
Pulling down a live Cobalt Strike beacon from a c2 server for analysis!
https://blog.spookysec.net/cs-beacon-analysis/
1 682
If you have ever wanted to detect a Cobalt Strike beacon installed through PowerShell, watch this video. I will also show you how to reverse the log to find the C2 server with CyberChef. (https://twitter.com/BriPwn)
https://www.youtube.com/watch?v=5GUx_6xWoeI
1 682
Update to nanodump!
You can now force WerFault.exe to dump LSASS for you. Thanks to @asaf_gilboa for the original research.
https://github.com/helpsystems/nanodump
