cobaltstrike
Ir al canal en Telegram
All about Cobalt Strike. New versions, articles and more.
Mostrar másEl país no está especificadoTecnologías y Aplicaciones42 376
1 682
Suscriptores
Sin datos24 horas
Sin datos7 días
Sin datos30 días
Archivo de publicaciones
1 682
SharpTerminatator is a C# port of ZeroMemoryEx's art piece called Terminator. It can be used with Cobalt Strike's execute-assembly or as a standalone executable to terminate AV/EDR processes.
1 682
Repost from Pwn3rzs
Cobalt Strike Artifact Kit - 15 March 2023
It was provided by a user as is, we take no responsibility.
Thanks again for the share from anonymous user :)
EDIT: A user notified that this is a repack of the official, so please pay attention, even if it's all just source code.
1 682
DropSpawn
CobaltStrike BOF для создания маяков с использованием DLL Application Directory Hijacking
download1 682
Hidden Desktop BOF
HVNC for Cobalt Strike (Hidden Desktop) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved, but the result is a similar experience.
1 682
A Cobalt Strike profile, modified it, and bypassed Crowdstrike & Sophos without encrypting the shellcode. Also bypassed all published YARA rules, sleep detections, and string detections around a CS beacon.
Blog: https://whiteknightlabs.com/2023/05/23/unleashing-the-unseen-harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion/
1 682
A little BOF that enumerates the protection level of a PP/PPL process.
https://github.com/rasta-mouse/PPEnum
1 682
Freeze.rs
Freeze•rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST
1 682
Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles
https://github.com/FortyNorthSecurity/AutoFunkt
1 682
Cool writeup by Xusheng Li on using Binary Ninja for reverse engineering a Cobalt Strike dropper
(credits @vector35)
https://binary.ninja/2022/07/22/reverse-engineering-cobalt-strike.html
1 682
Dir2json
.NET utility that lists directory contents with attributes and saves it as a .json file. It can be executed from the command line or Cobalt Strike's BOF. NET. Json2csv.ps1 script is also available for easier querying
https://github.com/bitsadmin/dir2json
1 682
Dir2json
.NET utility that lists directory contents with attributes and saves it as a .json file. It can be executed from the command line or Cobalt Strike's BOF. NET. Json2csv.ps1 script is also available for easier querying
https://github.com/bitsadmin/dir2json
1 682
Microsoft and Fortra crack down on malicious Cobalt Strike servers 🔥
https://therecord.media/cobalt-strike-abuse-microsoft-fortra-health-isac
1 682
A collection of random small Aggressor snippets that don't warrant their own repo
https://github.com/Octoberfest7/aggressor_snippets
1 682
Revisiting the User-Defined Reflective Loader Part 1: Simplifying Development
https://www.cobaltstrike.com/blog/revisiting-the-udrl-part-1-simplifying-development/
1 682
Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported APIs from the export table
https://github.com/TheD1rkMtr/NTDLLReflection
1 682
Cobalt Strike 4.8: (System) Call Me Maybe
https://www.cobaltstrike.com/blog/cobalt-strike-4-8-system-call-me-maybe/
