CobaltStrike
Argue:
argue whoami /totally /legit
argue powershell -command "get-adcomputer -Filter {...} .....
argue Spawnu/ runu:
PID/PPID spoofing:
# move to process
spawnu x86 C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
ppid MSEDGEbrowser proxying:
proxy pivoting:
Text/telegram notifications:
Last updated