
A BOF that runs unmanaged PEs inline
이것은 관리되지 않는(unmanaged) PE를 인라인으로 실행하고, 콘솔을 할당하지 않은 채(즉, conhost.exe를 생성하지 않고) 그 출력을 검색하는 Beacon Object File(BOF)입니다.

Summary: Run an unmanaged EXE/DLL inside Beacon's memory.
Usage: noconsolation [--local] [--inthread] [--link-to-peb] [--dont-unload] [--timeout 60] [-k] [--method funcname] [-w] [--no-output] [--alloc-console] [--close-handles] [--free-libraries wininet.dll,winhttp.dll] [--dont-save] [--list-pes] [--unload-pe pename] [--load-all-dependencies] [--load-all-dependencies-but advapi32.dll] [--load-dependencies wininet.dll] [--search-paths C:\Windows\Temp\] /path/to/binary.exe arg1 arg2
--local, -l Optional. The binary should be loaded from the target Windows machine
--inthread, -it Optional. Run the PE with the main thread. This might hang your beacon depending on the PE and its arguments.
--link-to-peb, -ltp Optional. Load the PE into the PEB
--dont-unload, -du Optional. If set, the DLL won't be unloaded.
--timeout NUM_SECONDS, -t NUM_SECONDS Optional. The number of seconds you wish to wait for the PE to complete running. Default 60 seconds. Set to 0 to disable
-k Optional. Overwrite the PE headers
--method EXPORT_NAME, -m EXPORT_NAME Optional. Method or function name to execute in case of DLL. If not provided, DllMain will be executed
-w Optional. Command line is passed to unmanaged DLL function in UNICODE format. (default is ANSI)
--no-output, -no Optional. Do not try to obtain the output
--alloc-console, -ac Optional. Allocate a console. This will spawn a new process
--close-handles, -ch Optional. Close Pipe handles once finished. If PowerShell was already ran, this will break the output for PowerShell in the future
--free-libraries, -fl DLL_A,DLL_B Optional. List of DLLs (previously loaded with --dont-unload) to be offloaded
--dont-save, -ds Optional. Do not save this binary in memory
--list-pes, -lpe Optional. List all PEs that have been loaded in memory
--unload-pe PE_NAME, -upe PE_NAME Optional. Unload from memory a PE
--load-all-dependencies, -lad Optional. Custom load all the PE's dependencies
--load-all-dependencies-but, -ladb DLL_A,DLL_B Optional. Custom load all the PE's dependencies except these
--load-dependencies, -ld DLL_A,DLL_B Optional. Custom load these PE's dependencies
--search-paths, -sp PATH_A,PATH_B Optional. Look for DLLs on these paths (system32 is the default)
/path/to/binary.exe Required. Full path to the windows EXE/DLL you wish you run inside Beacon. If already loaded, you can simply specify the binary name.
ARG1 ARG2 Optional. Parameters for the PE. Must be provided after the path
Example: noconsolation --local C:\windows\system32\windowspowershell\v1.0\powershell.exe $ExecutionContext.SessionState.LanguageMode
Example: noconsolation /tmp/mimikatz.exe privilege::debug token::elevate exit
Example: noconsolation --local C:\windows\system32\cmd.exe /c ipconfig
Example: noconsolation --list-pes
Example: noconsolation LoadedBinary.exe args
바이너리는 처음 실행된 후 자동으로 암호화되어 메모리에 저장됩니다. 즉, 매번 네트워크를 통해 바이너리를 보낼 필요가 없습니다.
이미 메모리에 저장된 바이너리를 실행하려면 전체 경로 대신 해당 이름만 지정하면 됩니다. 따라서 다음과 같이 실행하는 대신:
beacon> noconsolation --local C:\windows\system32\cmd.exe /c ipconfig
다음과 같이 실행하면 됩니다:
beacon> noconsolation cmd.exe /c ipconfig
메모리에 로드된 모든 바이너리를 나열하려면 --list-pes를 실행하십시오.
특정 바이너리 사용이 끝나서 메모리에서 내리려면 --unload-pe mimikatz.exe를 실행하십시오.
마지막으로, 바이너리를 자동으로 메모리에 로드하지 않고 실행하려면 --dont-save와 함께 실행하십시오.
PE의 모든 종속성을 자체 로드하여 모든 이미지 로드 이벤트를 피할 수 있습니다:
beacon> noconsolation --load-dependencies --link-to-peb /tmp/malware.exe
실행이 완료되면 PE와 해당 종속성은 자동으로 메모리에서 내려집니다.
Thread Local Storage를 사용하는 DLL은 지원되지 않습니다.