
Cobalt Strike에서 Windows의 GetLastError 메시지를 조회하는 aggressor 스크립트
Google 검색, net helpmsg, 또는 Microsoft Error Lookup Tool의 도움 없이 Cobalt Strike 클라이언트 내부에서 직접 GetLastError 코드로부터 오류 메시지를 얻을 수 있습니다. 오류 메시지는 aggressor 스크립트에 포함되어 있으며, beacon과의 상호 작용이 필요하지 않습니다.
aggressor 스크립트는 windows-lasterror-json 파일들로부터 자동으로 생성되고 업데이트됩니다.
beacon> ls //does-not-exists/c$
[*] Tasked beacon to list files in //does-not-exists/c$
[+] host called home, sent: 38 bytes
[-] could not open //does-not-exists/c$\*: 53
beacon> get-last-error 53
[*] ERROR_BAD_NETPATH
The network path was not found.