Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/
Unit 42
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
We show how metadata encryption and decryption contributes to making Cobalt Strike an effective emulator that is difficult to defend against.
DNS Tunneling using powershell to download and execute a beacon. Works in CLM.
https://github.com/Octoberfest7/DNS_Tunneling
https://github.com/Octoberfest7/DNS_Tunneling
GitHub
GitHub - Octoberfest7/DNS_Tunneling: DNS Tunneling using powershell to download and execute a payload. Works in CLM.
DNS Tunneling using powershell to download and execute a payload. Works in CLM. - Octoberfest7/DNS_Tunneling
Public variation of Titan Loader. Tweaks Cobalt Strike's behavior with Import Address Table Hooks
https://github.com/SecIdiot/TitanLdr
https://github.com/SecIdiot/TitanLdr
An aggressor script for Cobalt Strike to query Windows' GetLastError messages
https://github.com/Henkru/cs-get-last-error
https://github.com/Henkru/cs-get-last-error
GitHub
GitHub - Henkru/cs-get-last-error: An aggressor script for Cobalt Strike to query Windows' GetLastError messages
An aggressor script for Cobalt Strike to query Windows' GetLastError messages - Henkru/cs-get-last-error
PART 2: How I Met Your Beacon – Cobalt Strike
https://www.mdsec.co.uk/2022/07/part-2-how-i-met-your-beacon-cobalt-strike/
https://www.mdsec.co.uk/2022/07/part-2-how-i-met-your-beacon-cobalt-strike/
MDSec
PART 2: How I Met Your Beacon - Cobalt Strike - MDSec
Cobalt Strike is one of the most popular command-and-control frameworks, favoured by red teams and threat actors alike. In this blog post we will discuss strategies that can be used...
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process
https://github.com/ScriptIdiot/patchit
https://github.com/ScriptIdiot/patchit
GitHub
GitHub - ScriptIdiot/BOF-patchit: An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both…
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available. - ScriptIdiot/BOF-patchit
Oh my API, abusing TYK cloud API management to hide your malicious C2 traffic
https://shells.systems/oh-my-api-abusing-tyk-cloud-api-management-service-to-hide-your-malicious-c2-traffic/
https://shells.systems/oh-my-api-abusing-tyk-cloud-api-management-service-to-hide-your-malicious-c2-traffic/
Shells.Systems
Oh my API, abusing TYK cloud API management to hide your malicious C2 traffic - Shells.Systems
Estimated Reading Time: 10 minutes Hiding your malicious C2 traffic through legitimate channels is challenging nowadays, especially while CDN providers block all known techniques to use domain fronting to hide your malicious traffic. For that reason, I was…
Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF
https://github.com/ScriptIdiot/sw2-secinject
https://github.com/ScriptIdiot/sw2-secinject
GitHub
GitHub - ScriptIdiot/sw2-secinject: Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike…
Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF - ScriptIdiot/sw2-secinject
Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike
https://blog.malicious.group/automating-c2-infrastructure-with-terraform-nebula-caddy-and-cobalt-strike/
https://blog.malicious.group/automating-c2-infrastructure-with-terraform-nebula-caddy-and-cobalt-strike/
Malicious Group
Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike
In this post, I am going to show the readers how to build a fully automated C2 infrastructure using Terraform with Nebula's end-to-end encryption backend communication layer.
Using syscalls to bypass AV and EDR with Freeze and cobalt strike
https://www.youtube.com/watch?v=rElV-T6DIQ8
Download Freeze:
https://github.com/optiv/Freeze
https://www.youtube.com/watch?v=rElV-T6DIQ8
Download Freeze:
https://github.com/optiv/Freeze
YouTube
Using syscalls to bypass AV and EDR with Freeze and cobalt strike
Using syscalls to bypass AV and EDR with Freeze and cobalt strike
Download Freeze:
https://github.com/optiv/Freeze
Download Cobalt Strike:
https://www.cobaltstrike.com/
Download Freeze:
https://github.com/optiv/Freeze
Download Cobalt Strike:
https://www.cobaltstrike.com/