CobaltStrike

https://github.com/rvrsh3ll/FindFrontableDomains

can remove RWX function in beacon in mal profile

clear = clear beacon queue

Argue:

Argue take two commands, make the second look like the first:

argue whoami /totally /legit
argue powershell -command "get-adcomputer -Filter {...} .....
argue 

Spawnu/ runu:

run under a different desktop session

PID/PPID spoofing:

can be used to bypass / migrate to high integrity - i.e. svchost.exe

don't use for different desktop sessions

# move to process 
spawnu x86 C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
ppid MSEDGE

browser proxying:

Use browser pivot to take sessions from running browsers - jump onto password manager etc

proxy pivoting:

socks PORT

make sure beacon is interactive

Malleabale profiles:

use c2lint to check

Text/telegram notifications:

can enable telegram notifications by using beacon_initial to send. need aggressor, sleep and python

Last updated