cobaltstrike – Telegram
cobaltstrike
2.25K subscribers
28 photos
1 video
18 files
569 links
All about Cobalt Strike. New versions, articles and more.
Download Telegram
Forwarded from VX-SH
arsenal-kit20230919.tgz
3 MB
BooM 💥
👍12🆒4
Taking a quick look at the new Aggressor callbacks in Cobalt Strike 4.9.

https://rastamouse.me/cobalt-strike-aggressor-callbacks/
😁9🤡3🤔1
DojoLoader — Generic PE Loader for Prototyping Evasion Techniques

This is a versatile PE loader designed for prototyping evasion techniques. It supports downloading and executing encrypted shellcode, dynamic IAT hooking, and three Sleep obfuscation methods. Ideal for use with UDRL-less Beacon payloads from Cobalt Strike.

Blog Post:
https://www.naksyn.com/cobalt%20strike/2024/07/02/raising-beacons-without-UDRLs-teaching-how-to-sleep.html

Source:
https://github.com/naksyn/DojoLoader

#cobaltstrike #udrl #memory #evasion
4👍1🤡1🥱1😴1
NtDumpBOF

BOF port of the tool NativeDump which dump lsass using only Native APIs
42🥱2😴1
Voidmaw

A new technique that can be used to #bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders implemented by C2 beacons) or other problematic executables that will be flagged by the antimalware programs(such as mimikatz).
2👍1🔥1🤮1💩1🥱1