paranoidninja / Cobaltstrike-Detection
This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared
☆86Updated last year
Related projects ⓘ
Alternatives and complementary repositories for Cobaltstrike-Detection
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆72Updated 9 months ago
- ☆73Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆149Updated last year
- Lateral Movement☆119Updated last year
- ☆119Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆145Updated 11 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆83Updated 5 months ago
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆108Updated last month
- Two in one, patch lifetime powershell console, no more etw and amsi!☆80Updated 4 months ago
- ☆76Updated last year
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆82Updated 7 months ago
- A C# port from Invoke-GhostTask☆110Updated 10 months ago
- To audit the security of read-only domain controllers☆113Updated 11 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- Simple BOF to read the protection level of a process☆104Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- ApexLdr is a DLL Payload Loader written in C☆105Updated 4 months ago
- ☆61Updated 2 years ago
- ☆116Updated 2 months ago
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆88Updated last month
- Lateral Movement via the .NET Profiler☆76Updated 5 months ago
- Create Anti-Copy DRM Malware☆46Updated 3 months ago
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆163Updated last month
- ☆83Updated 6 months ago
- ☆92Updated 9 months ago
- ☆79Updated 6 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆88Updated 9 months ago