en
Feedback
cobaltstrike

cobaltstrike

Open in Telegram

All about Cobalt Strike. New versions, articles and more.

Show more
The country is not specifiedTechnologies & Applications42 376
1 682
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Cobalt Strike: Using Known Private Keys To Decrypt Traffic – Part 2 https://blog.nviso.eu/2021/10/27/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-2/

DLL Hijack Search Order Enumeration BOF https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF

photo content

This new version brings an update to the statistics in file 1768.json. MD5: C410C38FC2B5F0B2C3104D7FC1D35C58 SHA256: 9374650575E0F15331CE05ACFD2BFA4CD6EBEB1497207B9B6D4B1F7A0214457D

Cobalt Strike: Using Known Private Keys To Decrypt Traffic – Part 1 https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/

CVE-2021-36798 Exp: Cobalt Strike < 4.4 Dos https://github.com/JamVayne/CobaltStrikeDos

photo content

Parser Cobalt Strike malleable C2 profiles. https://github.com/brett-fitz/pyMalleableProfileParser

DCOM_AV_EXEC (+ AV_Bypass_Framework_V3) https://gitlab.com/theepicpowner/dcom_av_exec

A BOF to interact with COM objects associated with the Windows software firewall. https://github.com/EspressoCake/Firewall_Walker_BOF

PIC your Katz! Say hello to HandleKatz, our position independent Lsass dumper abusing cloned handles, direct system calls and a modified version of minidumpwritedump() brought to you by @thefLinkk https://github.com/EspressoCake/HandleKatz_BOF

Defining Cobalt Strike Components So You Can BEA-CONfident in Your Analysis https://www.mandiant.com/resources/defining-cobalt-strike-components

Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File https://github.com/EncodeGroup/BOF-RegSave

photo content

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching. https://github.com/outflanknl/WdToggle