Pentesting with Kali Linux
24.1K subscribers
19 photos
262 files
312 links
Download Telegram
CobaltStrikeScan

Scan files or process memory for Cobalt Strike beacons and parse their configuration.

CobaltStrikeScan scans Windows process memory for evidence of DLL injection (classic or reflective injection) and performs a YARA scan on the target process' memory for Cobalt Strike v3 and v4 beacon signatures.

Alternatively, CobaltStrikeScan can perform the same YARA scan on a file supplied by absolute or relative path as a command-line argument.

If a Cobalt Strike beacon is detected in the file or process, the beacon's configuration will be parsed and displayed to the console
OWASP Automated Threat Handbook Web Applications:
The OWASP Automated Threat Handbook provides actionable information and resources to help defend against automated threats to web applications
#cobaltstrike

https://github.com/rvrsh3ll/BOF_Collection

tool enables the compilation of a C# program that will execute arbitrary PowerShell code, without launching PowerShell processes through the use of runspace.

https://github.com/Mr-B0b/SpaceRunner

https://github.com/m57/cobaltstrike_bofs

https://shells.systems/octopus-v1-0-stable-cobalt-strike-deployment-much-more/

https://github.com/pandasec888/taowu-cobalt-strike

https://usualsuspect.re/article/cobalt-strikes-malleable-c2-under-the-hood

https://github.com/cube0x0/SharpeningCobaltStrike

https://github.com/Verizon/redshell

https://securityonline.info/crossc2-framework/

https://github.com/ustayready/SharpHose

Another role released in this effort to automate all the things using ansible.
This time it's for Route53, and it's interactive!
https://github.com/jfmaes/Red-Route53-Interactive

EC2-R53-Cobalt-Strike check
all that is left now is RedElk and the blogpost :)

Custom DLL injection with Cobalt Strike's Beacon Object Files

https://x64sec.sh/custom-dll-injection-with-cobalt-strike/

Cobalt Strike Malleable Profile Inline Patch Template: A Position Independent Code (PIC) Code Template For Creating Shellcode That Can Be Appended In Stage / Post-Ex Blocks. Made for C Programmers

https://github.com/SecIdiot/CobaltPatch

https://github.com/Apr4h/CobaltStrikeScan

Cobalt Strike Aggressor script to generate GadgetToJScript payloads

https://github.com/EncodeGroup/AggressiveGadgetToJScript

DCOM-Lateral-Movement

https://github.com/Yaxser/CobaltStrike-BOF

Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File

https://github.com/EncodeGroup/BOF-RegSave

Cobalt Strike Shellcode Loader by Golang

https://github.com/timwhitez/Doge-Loader

CS-Avoid-killing Loader

https://github.com/Gality369/CS-Loader
"The enemy does not care what systems were in scope for testing. Protect your weak points." - The Art of Cyber War