paranoidninja / Cobaltstrike-Detection
This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared
☆88Updated last year
Alternatives and similar repositories for Cobaltstrike-Detection:
Users that are interested in Cobaltstrike-Detection are comparing it to the libraries listed below
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆73Updated 11 months ago
- Lateral Movement☆122Updated last year
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆149Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- ☆73Updated last year
- I have documented all of the AMSI patches that I learned till now☆69Updated last year
- Create Anti-Copy DRM Malware☆51Updated 5 months ago
- Detect WFP filters blocking EDR communications☆85Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆92Updated last year
- Example code samples from our ScriptBlock Smuggling Blog post☆87Updated 7 months ago
- ApexLdr is a DLL Payload Loader written in C☆106Updated 6 months ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆83Updated 7 months ago
- ☆92Updated 11 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- Execute commands in other Sessions☆84Updated 6 months ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 6 months ago
- To audit the security of read-only domain controllers☆114Updated last year
- Do some DLL SideLoading magic☆77Updated last year
- ☆122Updated last year
- Adversary Emulation Framework☆63Updated 6 months ago
- ☆80Updated 8 months ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- Windows Persistence Toolkit in C#☆36Updated 2 years ago
- ☆92Updated 4 months ago
- ☆85Updated 8 months ago
- Implant drop-in for EDR testing☆132Updated last year
- A BOF to enumerate system process, their protection levels, and more.☆113Updated 2 months ago
- Detect EDR's exceptions by inspecting processes' loaded modules☆124Updated 10 months ago
- AzureAD beacon object files☆108Updated last month