CobaltStrikeScan
Scan files or process memory for Cobalt Strike beacons and parse their configuration.
CobaltStrikeScan scans Windows process memory for evidence of DLL injection (classic or reflective injection) and performs a YARA scan on the target process' memory for Cobalt Strike v3 and v4 beacon signatures.
Alternatively, CobaltStrikeScan can perform the same YARA scan on a file supplied by absolute or relative path as a command-line argument.
If a Cobalt Strike beacon is detected in the file or process, the beacon's configuration will be parsed and displayed to the console
Scan files or process memory for Cobalt Strike beacons and parse their configuration.
CobaltStrikeScan scans Windows process memory for evidence of DLL injection (classic or reflective injection) and performs a YARA scan on the target process' memory for Cobalt Strike v3 and v4 beacon signatures.
Alternatively, CobaltStrikeScan can perform the same YARA scan on a file supplied by absolute or relative path as a command-line argument.
If a Cobalt Strike beacon is detected in the file or process, the beacon's configuration will be parsed and displayed to the console
OWASP Automated Threat Handbook Web Applications:
The OWASP Automated Threat Handbook provides actionable information and resources to help defend against automated threats to web applications
The OWASP Automated Threat Handbook provides actionable information and resources to help defend against automated threats to web applications
#cobaltstrike
https://github.com/rvrsh3ll/BOF_Collection
tool enables the compilation of a C# program that will execute arbitrary PowerShell code, without launching PowerShell processes through the use of runspace.
https://github.com/Mr-B0b/SpaceRunner
https://github.com/m57/cobaltstrike_bofs
https://shells.systems/octopus-v1-0-stable-cobalt-strike-deployment-much-more/
https://github.com/pandasec888/taowu-cobalt-strike
https://usualsuspect.re/article/cobalt-strikes-malleable-c2-under-the-hood
https://github.com/cube0x0/SharpeningCobaltStrike
https://github.com/Verizon/redshell
https://securityonline.info/crossc2-framework/
https://github.com/ustayready/SharpHose
Another role released in this effort to automate all the things using ansible.
This time it's for Route53, and it's interactive!
https://github.com/jfmaes/Red-Route53-Interactive
EC2-R53-Cobalt-Strike check
all that is left now is RedElk and the blogpost :)
Custom DLL injection with Cobalt Strike's Beacon Object Files
https://x64sec.sh/custom-dll-injection-with-cobalt-strike/
Cobalt Strike Malleable Profile Inline Patch Template: A Position Independent Code (PIC) Code Template For Creating Shellcode That Can Be Appended In Stage / Post-Ex Blocks. Made for C Programmers
https://github.com/SecIdiot/CobaltPatch
https://github.com/Apr4h/CobaltStrikeScan
Cobalt Strike Aggressor script to generate GadgetToJScript payloads
https://github.com/EncodeGroup/AggressiveGadgetToJScript
DCOM-Lateral-Movement
https://github.com/Yaxser/CobaltStrike-BOF
Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File
https://github.com/EncodeGroup/BOF-RegSave
Cobalt Strike Shellcode Loader by Golang
https://github.com/timwhitez/Doge-Loader
CS-Avoid-killing Loader
https://github.com/Gality369/CS-Loader
https://github.com/rvrsh3ll/BOF_Collection
tool enables the compilation of a C# program that will execute arbitrary PowerShell code, without launching PowerShell processes through the use of runspace.
https://github.com/Mr-B0b/SpaceRunner
https://github.com/m57/cobaltstrike_bofs
https://shells.systems/octopus-v1-0-stable-cobalt-strike-deployment-much-more/
https://github.com/pandasec888/taowu-cobalt-strike
https://usualsuspect.re/article/cobalt-strikes-malleable-c2-under-the-hood
https://github.com/cube0x0/SharpeningCobaltStrike
https://github.com/Verizon/redshell
https://securityonline.info/crossc2-framework/
https://github.com/ustayready/SharpHose
Another role released in this effort to automate all the things using ansible.
This time it's for Route53, and it's interactive!
https://github.com/jfmaes/Red-Route53-Interactive
EC2-R53-Cobalt-Strike check
all that is left now is RedElk and the blogpost :)
Custom DLL injection with Cobalt Strike's Beacon Object Files
https://x64sec.sh/custom-dll-injection-with-cobalt-strike/
Cobalt Strike Malleable Profile Inline Patch Template: A Position Independent Code (PIC) Code Template For Creating Shellcode That Can Be Appended In Stage / Post-Ex Blocks. Made for C Programmers
https://github.com/SecIdiot/CobaltPatch
https://github.com/Apr4h/CobaltStrikeScan
Cobalt Strike Aggressor script to generate GadgetToJScript payloads
https://github.com/EncodeGroup/AggressiveGadgetToJScript
DCOM-Lateral-Movement
https://github.com/Yaxser/CobaltStrike-BOF
Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File
https://github.com/EncodeGroup/BOF-RegSave
Cobalt Strike Shellcode Loader by Golang
https://github.com/timwhitez/Doge-Loader
CS-Avoid-killing Loader
https://github.com/Gality369/CS-Loader
GitHub
GitHub - rvrsh3ll/BOF_Collection: Various Cobalt Strike BOFs
Various Cobalt Strike BOFs. Contribute to rvrsh3ll/BOF_Collection development by creating an account on GitHub.
AppSec Ezine - 347th Edition https://pathonproject.com/zb/?d27265301502e082#PM2x3urqVFrKvqkRlVWuK+5jE3zhGXcRlVhlkIkXRGE=
"The enemy does not care what systems were in scope for testing. Protect your weak points." - The Art of Cyber War