cobaltstrike
2.35K subscribers
28 photos
1 video
18 files
579 links
All about Cobalt Strike. New versions, articles and more.
Download Telegram
Reviewed, Modified RunCoff arguments.
Added Cleanup for beacon compatability failure, and ran code beautifier on the C#

https://github.com/trustedsec/CS_COFFLoader
❀2
BOFMask

BOFMask is a tool designed to conceal Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF). By applying a XOR mask and modifying memory protection settings, BOFMask enables users to execute BOFs without exposing Beacon, thereby avoiding detection by EDR products that scan system memory.

Research:
https://securityintelligence.com/posts/how-to-hide-beacon-during-bof-execution/

Source:
https://github.com/xforcered/bofmask
πŸ‘4
Winsocket implementation for Cobalt Strike. Used to communicate with the victim using winsockets instead of the traditional ways.

https://github.com/WKL-Sec/Winsocky/
πŸ‘3
Forwarded from VX-SH
arsenal-kit20230919.tgz
3 MB
BooM πŸ’₯
πŸ‘12πŸ†’4
Taking a quick look at the new Aggressor callbacks in Cobalt Strike 4.9.

https://rastamouse.me/cobalt-strike-aggressor-callbacks/
😁9🀑3πŸ€”1
This media is not supported in your browser
VIEW IN TELEGRAM
🀣12🀑4πŸ‘Ž2πŸ‘1πŸ”₯1