en
Feedback
cobaltstrike

cobaltstrike

Open in Telegram

All about Cobalt Strike. New versions, articles and more.

Show more
The country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551. https://github.com/tijme/kernel-mii

A simple BOF that tries to free the memory region where the User Defined Reflective Loader is stored. https://github.com/S4ntiagoP/freeBokuLoader

Arsenal Kit Update: Thread Stack Spoofing https://github.com/mgeeky/ThreadStackSpoofer

Cobalt strike CNA script to notify you via Discord whenever there is a new beacon. https://github.com/ScriptIdiot/BeaconNotifier-Discord

List/Read contents of Zip files (in memory and without extraction) using CobaltStrike's Execute-Assembly https://github.com/OG-Sadpanda/SharpZippo.git

This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently, it supports RBCD, Constrained, Constrained w/Protocol Transition, and Unconstrained Delegation checks. https://github.com/IcebreakerSecurity/DelegationBOF

Beacon Object File to locate and suspend the threads hosting the Event Log service https://github.com/nick-frischkorn/SuspendEventLogBOF

Calling Cobalt Strike aliases from other aliases (kinda) https://passthehashbrowns.github.io/cobalt-strike-aliases-kinda

ElevatedEvents:Yet Another EventViewer UAC bypass via .NET deserialization discovered by @orange_8361 made into a reflective dll to use with Cobalt Strike. Includes a simple Defender Bypass baked in as this UAC bypass is now detected. https://github.com/jsecu/ElevatedEvents

RDI implementation of NetUserAdd bypasses AV https://github.com/crisprss/BypassUserAdd

CNA that interacts with a JAR file to dynamically rename GUI tabs within Cobalt Strike from a JSON file. https://github.com/EspressoCake/DynamicTabRename

CobaltStrike and Google Auth twice https://github.com/HKirito/GoogleAuth

Hunting Cobalt Strike Servers A comprehensive view on the techniques used to fingerprint Cobalt Strike’s C2s https://bank-security.medium.com/hunting-cobalt-strike-servers-385c5bedda7b

BOF implementation of the research by @jonaslyk and the drafted PoC from @LloydLabs https://github.com/EspressoCake/Self_Deletion_BOF

Introducing pyCobaltHound – Let Cobalt Strike unleash the Hound https://blog.nviso.eu/2022/05/09/introducing-pycobalthound/

Cobalt Strike Analysis and Tutorial: CS Metadata Encoding and Decoding https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/

EventViewerUAC_BOF: Event Viewer deserialization UAC bypass https://securityonline.info/eventvieweruac_bof-event-viewer-deserialization-uac-bypass/

Remote Operations BOF This repo serves as an addition to our previously released SA Repo. https://github.com/trustedsec/CS-Remote-OPs-BOF