cobaltstrike
1.7K subscribers
24 photos
1 video
18 files
545 links
All about Cobalt Strike. New versions, articles and more.
Download Telegram
Reviewed, Modified RunCoff arguments.
Added Cleanup for beacon compatability failure, and ran code beautifier on the C#

https://github.com/trustedsec/CS_COFFLoader
BOFMask

BOFMask is a tool designed to conceal Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF). By applying a XOR mask and modifying memory protection settings, BOFMask enables users to execute BOFs without exposing Beacon, thereby avoiding detection by EDR products that scan system memory.

Research:
https://securityintelligence.com/posts/how-to-hide-beacon-during-bof-execution/

Source:
https://github.com/xforcered/bofmask
Forwarded from VX-SH
arsenal-kit20230919.tgz
3 MB
BooM 💥
Taking a quick look at the new Aggressor callbacks in Cobalt Strike 4.9.

https://rastamouse.me/cobalt-strike-aggressor-callbacks/