en
Feedback
cobaltstrike

cobaltstrike

Open in Telegram

All about Cobalt Strike. New versions, articles and more.

Show more
The country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
FuckThatPacker is now integrated to CobaltStrike. You can now generate obufscated powershell payloads directly within CobaltStrike https://github.com/Unknow101/FuckThatPacker

Implementing Syscalls in Cobalt Strike Part 1 - Battling Imports and Dependencies https://blog.xenoscr.net/2022/03/12/Implementing-Syscalls-in-Cobalt-Strike-Part-1-Battling-Imports-and-Dependencies.html

BOF and Shellcode for full DLL unhooking using dynamic syscalls https://github.com/cube0x0/SyscallPack

Parser logs created by Cobalt Strike and creates an SQLite DB which can be used to create custom reports. https://github.com/Patrick-DE/Cobaltstrike-logparser

Did someone say Cobalt Strike?

Report on weird chain targetting India with cobalt strike and compromised domain like covid.comesa.int used to spread malicious ISOs and acts as C2

Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc. https://github.com/wumb0/rust_bof

Beacon Object File & C# project to check LDAP signing https://github.com/cube0x0/LdapSignCheck

BofRoast. Beacon Object File repo for roasting Active Directory https://github.com/cube0x0/BofRoast

Cobalt Strike Being Distributed to Vulnerable MS-SQL Servers https://asec.ahnlab.com/en/31811/

SourcePoint v2.2 releases: polymorphic C2 profile generator for Cobalt Strike C2s https://securityonline.info/sourcepoint-polymorphic-c2-profile-generator-for-cobalt-strike-c2s/

Yeah!
Yeah!

Ever fancied running Cobalt Strike BOFs with Python? Using COFFLoader and BOF2shellcode you can! Blogpost and PoC: https://www.naksyn.com/injection/2022/02/16/running-cobalt-strike-bofs-from-python.html

Staged vs Stageless payloads, what difference does it make in AV evasion? Well, someone made a comment today and I spent the last 12 hours writing a new blogpost! https://blog.spookysec.net/stage-v-stageless-1/