es
Feedback
cobaltstrike

cobaltstrike

Ir al canal en Telegram

All about Cobalt Strike. New versions, articles and more.

Mostrar más
El país no está especificadoTecnologías y Aplicaciones42 376
1 682
Suscriptores
Sin datos24 horas
Sin datos7 días
Sin datos30 días
Archivo de publicaciones
SharpTerminatator is a C# port of ZeroMemoryEx's art piece called Terminator. It can be used with Cobalt Strike's execute-ass
SharpTerminatator is a C# port of ZeroMemoryEx's art piece called Terminator. It can be used with Cobalt Strike's execute-assembly or as a standalone executable to terminate AV/EDR processes.

Repost from Pwn3rzs
Cobalt Strike Artifact Kit - 15 March 2023 It was provided by a user as is, we take no responsibility. Thanks again for the share from anonymous user :) EDIT: A user notified that this is a repack of the official, so please pay attention, even if it's all just source code.

DropSpawn CobaltStrike BOF для создания маяков с использованием DLL Application Directory Hijacking download
DropSpawn CobaltStrike BOF для создания маяков с использованием DLL Application Directory Hijacking download

Hidden Desktop BOF HVNC for Cobalt Strike (Hidden Desktop) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved, but the result is a similar experience.

A Cobalt Strike profile, modified it, and bypassed Crowdstrike & Sophos without encrypting the shellcode. Also bypassed all published YARA rules, sleep detections, and string detections around a CS beacon. Blog: https://whiteknightlabs.com/2023/05/23/unleashing-the-unseen-harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion/

Russian translate documentation for CSv4.7

Cobalt Strike Beacon implement in Rust https://github.com/b1tg/cobaltstrike-beacon-rust

A little BOF that enumerates the protection level of a PP/PPL process. https://github.com/rasta-mouse/PPEnum

Freeze.rs Freeze•rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST
Freeze.rs Freeze•rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST

😂
😂

Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles https://github.com/FortyNorthSecurity/AutoFunkt

Cool writeup by Xusheng Li on using Binary Ninja for reverse engineering a Cobalt Strike dropper (credits @vector35) https://binary.ninja/2022/07/22/reverse-engineering-cobalt-strike.html

Dir2json .NET utility that lists directory contents with attributes and saves it as a .json file. It can be executed from the command line or Cobalt Strike's BOF. NET. Json2csv.ps1 script is also available for easier querying https://github.com/bitsadmin/dir2json

Dir2json .NET utility that lists directory contents with attributes and saves it as a .json file. It can be executed from the command line or Cobalt Strike's BOF. NET. Json2csv.ps1 script is also available for easier querying https://github.com/bitsadmin/dir2json

Microsoft and Fortra crack down on malicious Cobalt Strike servers 🔥 https://therecord.media/cobalt-strike-abuse-microsoft-fortra-health-isac

A collection of random small Aggressor snippets that don't warrant their own repo https://github.com/Octoberfest7/aggressor_snippets

Revisiting the User-Defined Reflective Loader Part 1: Simplifying Development https://www.cobaltstrike.com/blog/revisiting-the-udrl-part-1-simplifying-development/

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported APIs from the export table https://github.com/TheD1rkMtr/NTDLLReflection