CobaltStrike
https://github.com/rvrsh3ll/FindFrontableDomains
can remove RWX function in beacon in mal profile
clear = clear beacon queue
Argue:
Argue take two commands, make the second look like the first:
argue whoami /totally /legit
argue powershell -command "get-adcomputer -Filter {...} .....
argue Spawnu/ runu:
run under a different desktop session
PID/PPID spoofing:
can be used to bypass / migrate to high integrity - i.e. svchost.exe
don't use for different desktop sessions
# move to process
spawnu x86 C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
ppid MSEDGEbrowser proxying:
Use browser pivot to take sessions from running browsers - jump onto password manager etc
proxy pivoting:
socks PORT
make sure beacon is interactive
Malleabale profiles:
use c2lint to check
Text/telegram notifications:
can enable telegram notifications by using beacon_initial to send. need aggressor, sleep and python
Last updated