很棒的 CobaltStrike 资源列表
# Awesome CobaltStrike   ### 目录 - [0x00 简介](#0x00-introduction) - [0x01 文章与视频](#0x01-articles--videos) - [1. 基础知识](#1-basic-knowledge) - [2. 破解与定制](#2-crack-and-customisation) - [3. 实用技巧](#3-useful-trick) - [4. CobaltStrike 隐匿](#4-cobaltstrike-hide) - [5. CobaltStrike 分析](#5-cobaltstrike-analysis) - [6. CobaltStrike 视频](#6-cobaltstrike-video) - [0x02 C2 配置文件](#0x02-c2-profiles) - [0x03 BOF](#0x03-bof) - [0x04 Aggressor 脚本](#0x04-aggressor-script) - [0x05 相关工具](#0x05-related-tools) - [0x06 相关资源](#0x06-related-resources) ### 0x00 简介 1. 第一部分是精选的关于 CobaltStrike 的高质量文章合集 2. 第三部分是关于 BOF 新特性资源的整合 3. 这个项目旨在解决在需要时找不到合适的 Aggressor 脚本或 BOF 的问题 4. 如果本仓库没有涵盖到优质内容,欢迎提交 PR ### 0x01 文章与视频 #### 1. 基础知识 1. [Cobalt_Strike_wiki](https://github.com/aleenzz/Cobalt_Strike_wiki) 2. [Cobalt Strike 手册](https://wbglil.gitbook.io/cobalt-strike/) 3. [CobaltStrike4.0笔记](https://github.com/Snowming04/CobaltStrike4.0_related) 4. [CobaltStrike相关网络文章集合](https://4hou.win/wordpress/?cat=306) 5. [Cobalt Strike 外部 C2 之原理篇](http://blog.leanote.com/post/snowming/50448511de58) 6. [Cobalt Strike 桌面控制问题的解决(以及屏幕截图等后渗透工具)](http://blog.leanote.com/post/snowming/32fabf2deae1) 7. [Cobalt Strike & MetaSploit 联动](http://blog.leanote.com/post/snowming/43cef4b64cbd) 8. [Cobalt-Strike-CheatSheet](https://github.com/S1ckB0y1337/Cobalt-Strike-CheatSheet) 9. [Cobalt Strike 的 MITRE TTPs](https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence) 10. [使用 Cobalt Strike 进行红队行动 (2019)](https://github.com/martabyte/Red-Team-Ops/blob/main/Red-Team-Ops.md) 11. [Cobalt Strike:概览](https://blog.nviso.eu/2022/03/22/cobalt-strike-overview-part-7/) 12. [CobaltStrike插件开发](https://t.zsxq.com/04RfYVNzb) 13. [Cobalt Strike 中文 Wiki](https://github.com/XXC385/Cobalt-Strike-Start) #### 2. 破解与定制 1. [IntelliJ-IDEA修改cobaltstrike](https://pingmaoer.github.io/2020/06/08/IntelliJ-IDEA修改cobaltstrike/) 2. [CobaltStrike二次开发环境准备](https://pingmaoer.github.io/2020/06/24/CobaltStrike二次开发环境准备/) 3. [Cobal Strike 自定义OneLiner](https://evi1cg.me/archives/Custom_Oneliner.html) 4. [通过反射DLL注入来构建后渗透模块(第一课)](https://payloads.online/archivers/2020-03-02/1) 5. [Cobalt Strike Aggressor Script (第一课)](https://payloads.online/archivers/2020-03-02/4) 6. [Cobalt Strike Aggressor Script (第二课)](https://payloads.online/archivers/2020-03-02/5) 7. [在 Cobaltstrike Artifact Kit 中实现系统调用](https://br-sn.github.io/Implementing-Syscalls-In-The-CobaltStrike-Artifact-Kit/) 8. [Cobalt Strike 4.0 认证及修补过程](https://xz.aliyun.com/t/8557) 9. [使用ReflectiveDLLInjection武装你的CobaltStrike](https://mp.weixin.qq.com/s/-Inh6uWV9YCz0zQYfitceA) 10. [绕过 cobaltstrike beacon 配置扫描](https://mp.weixin.qq.com/s/fhcTTWV4Ddz4h9KxHVRcnw) 11. [针对目标定制 Cobalt Strike](https://blog.xpnsec.com/tailoring-cobalt-strike-on-target/) 12. [COFFLOADER:构建你自己的内存加载器或如何运行 BOF](https://www.trustedsec.com/blog/coffloader-building-your-own-in-memory-loader-or-how-to-run-bofs/) 13. [又一个 Cobalt Strike Stager:GUID 版](https://www.guidepointsecurity.com/yet-another-cobalt-strike-loader-guid-edition/) 14. [Cobalt Strike4.3 破解日记](https://blog.pr0ph3t.com/posts/Cobalt-Strike4.3%E7%A0%B4%E8%A7%A3%E6%97%A5%E8%AE%B0/) 15. [Cobalt Strike 进程创建与对应的 Syslog 日志分析](https://hausec.com/2021/07/26/cobalt-strike-and-tradecraft/) 16. [面具背后:使用定时器动态欺骗调用栈](https://www.cobaltstrike.com/blog/behind-the-mask-spoofing-call-stacks-dynamically-with-timers/) #### 3. 实用技巧 1. [Cobalt Strike 鱼叉式钓鱼](https://evi1cg.me/archives/spear_phish.html) 2. [在 Windows 中运行 CS -- teamserver.bat](https://evi1cg.me/archives/teamserver.html) 3. [通过 CS 进行远程 NTLM 中继 -- 与 CVE_2018_8581 相关](https://evi1cg.me/archives/Remote_NTLM_relaying_through_CS.html) 4. [Cobalt Strike 连接 VPN](http://blog.leanote.com/post/snowming/82b418239c13) 5. [渗透神器CS3.14搭建使用及流量分析](https://mp.weixin.qq.com/s/DG87HFrwHf25_M2Dnfdx3g) 6. [CobaltStrike生成免杀shellcode](https://mp.weixin.qq.com/s/G1hmsDVTO2208Ymlia_ggQ) 7. [CS-notes](https://github.com/kluo84/CS-notes)--一系列CS的使用技巧笔记 8. [使用 Cobalt Strike 对 Linux 主机进行后渗透](http://blog.leanote.com/post/snowming/c34f9defe00c) 9. [Cobalt Strike 使用代理的监听器](http://blog.leanote.com/post/snowming/2ec80f7823e0) 10. [Cobalt Strike 连接 VPN](http://blog.leanote.com/post/snowming/82b418239c13) 11. [CS 4.0 SMB Beacon](http://blog.leanote.com/post/snowming/8b7ce0f84c03) 12. [Cobalt Strike 浏览器跳板攻击](http://blog.leanote.com/post/snowming/4e07af1cab60) 13. [Cobalt Strike 中 Bypass UAC](http://blog.leanote.com/post/snowming/b6f671477095) 14. [一起探索Cobalt Strike的ExternalC2框架](https://www.anquanke.com/post/id/103395/) 15. [深入探索Cobalt Strike的ExternalC2框架](https://xz.aliyun.com/t/2239) 16. [Cobalt Strike的特殊功能(external_C2)探究](https://www.anquanke.com/post/id/86980/) 17. [.NET 程序集、Cobalt Strike 大小限制与反射的故事](https://redteamer.tips/a-tale-of-net-assemblies-cobalt-strike-size-constraints-and-reflection/) 18. [AppDomain.AssemblyResolve](https://offensivedefence.co.uk/posts/assembly-resolve/) 19. [从webshell建立代理上线不出网的内网机器](https://mp.weixin.qq.com/s/mNCROss5pa4rkrWIIfjVfQ) 20. [在Cobalt Strike BOF中进行直接系统调用](https://mp.weixin.qq.com/s/TLyQOupzep1BN7_nbjCXeQ) 21. [在 Cobalt Strike 的 Artifact Kit 中使用直接系统调用](https://www.youtube.com/watch?v=mZyMs2PP38w&feature=youtu.be&ab_channel=RaphaelMudge) 22. [Cobalt Strike 的 Staging 与配置信息提取](https://blog.securehat.co.uk/cobaltstrike/extracting-config-from-cobaltstrike-stager-shellcode) 23. [使用 Artifact Kit 创建代理 DLL](https://www.cobaltstrike.com/blog/create-a-proxy-dll-with-artifact-kit/) 24. [攻击者滥用 MSBuild 绕过防御并植入 Cobalt Strike Beacon](https://isc.sans.edu/forums/diary/Attackers+are+abusing+MSBuild+to+evade+defenses+and+implant+Cobalt+Strike+beacons/28180/#comments) 25. [使用 LiquidSnake 进行横向移动](https://tw1sm.github.io/2021-09-13-liquidsnake/) 26. [来自 OtterHacker 的 CoffLoader](https://otterhacker.github.io/Malware/CoffLoader.html#introduction) #### 4. CobaltStrike 隐匿 1. [CobaltStrike证书修改躲避流量审查](https://mp.weixin.qq.com/s/sYfvD0XQqi6BFw70_jrv5Q) 2. [CS 合法证书 + Powershell 上线](http://blog.leanote.com/post/snowming/6a724671de78) 3. [Cobalt Strike 团队服务器隐匿](http://blog.leanote.com/post/snowming/d5d2b4ba20d0) 4. [红队基础建设:隐藏你的C2 server](https://xz.aliyun.com/t/4509) 5. [使用 Apache mod_rewrite 的 Cobalt Strike HTTP C2 重定向器](https://bluescreenofjeff.com/2016-06-28-cobalt-strike-http-c2-redirectors-with-apache-mod_rewrite/) 6. [深入研究cobalt strike malleable C2配置文件](https://xz.aliyun.com/t/2796) 7. [美丽新世界:Malleable C2](http://www.harmj0y.net/blog/redteaming/a-brave-new-world-malleable-c2/) 8. [如何为 Cobalt Strike 编写 Malleable C2 配置文件](https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/) 9. [轻松实现随机化的 Malleable C2 配置文件](https://bluescreenofjeff.com/2017-08-30-randomized-malleable-c2-profiles-made-easy/) 10. [关于CobaltStrike的Stager被扫问题](https://mp.weixin.qq.com/s/0MPM3bysJJYr5jbRnES_Vg) 11. [Beacon Stager listener 去特征](https://mp.weixin.qq.com/s/HibtLfikI_0ezcLVCRxqaA) 12. [检测与隐藏Cobaltstrike服务器](https://hosch3n.github.io/2020/12/16/%E6%A3%80%E6%B5%8B%E4%B8%8E%E9%9A%90%E8%97%8FCobaltstrike%E6%9C%8D%E5%8A%A1%E5%99%A8/) 13. [记一次cs bypass卡巴斯基内存查杀](https://xz.aliyun.com/t/9224) 14. [cs bypass卡巴斯基内存查杀 2](https://xz.aliyun.com/t/9399) 15. [Cobalt Strike – 绕过 C2 网络检测](https://newtonpaul.com/cobalt-strike-bypassing-c2-network-detections/) 16. [Cobalt Strike特征隐藏](https://www.cnblogs.com/Xy--1/p/14396744.html) 17. [Cobalt Strike 反溯源之 CDN 篇](https://mp.weixin.qq.com/s/9taI6KQzKy2vcKHJXnwgmg) 18. [释放无形之力:利用 Cobalt Strike 配置文件实现 EDR 规避](https://whiteknightlabs.com/2023/05/23/unleashing-the-unseen-harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion/) #### 5. CobaltStrike 分析 1. 用于检测 Cobalt Strike Beacon 的 Volatility 插件。[博客](https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html)|[工具集](https://github.com/RomanEmelyanov/CobaltStrikeForensic) 2. [逆向分析Cobalt Strike安装后门](https://mp.weixin.qq.com/s/VHpcHzLc829hmQjrx1139A) 3. [分析cobaltstrike c2 协议](https://github.com/verctor/Cobalt_Homework) 4. 用于解密 Cobalt Strike 认证文件的小型[工具](https://github.com/Mkv4/cobaltstrike-authfile-decrypt) 5. [Cobalt Strike 的 ExternalC2](https://xz.aliyun.com/t/6565) 6. [通过命名管道分析检测 Cobalt Strike 默认模块](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) 7. [浅析CobaltStrike Beacon Staging Server扫描](https://mp.weixin.qq.com/s/WUf96myUi8F3X_eNWPRTdw) 8. [反击退役的 Cobalt Strike:一个遗留漏洞的观察](https://research.nccgroup.com/2020/06/15/striking-back-at-retired-cobalt-strike-a-look-at-a-legacy-vulnerability/) 9. [为了乐趣与收益分析 Cobalt Strike](https://www.randhome.io/blog/2020/12/20/analyzing-cobalt-strike-for-fun-and-profit/) 10. [Cobalt Strike 远程线程检测](https://medium.com/@olafhartong/cobalt-strike-remote-threads-detection-206372d11d0f) 11. [检测 Cobalt Strike 的艺术与科学](https://talos-intelligence-site.s3.amazonaws.com/production/document_files/files/000/095/031/original/Talos_Cobalt_Strike.pdf) 12. [识别恶意 Cobalt Strike 服务器的多方法方案](https://go.recordedfuture.com/hubfs/reports/cta-2019-0618.pdf) 13. [如何在内存取证中检测 Cobalt Strike 活动](https://www.andreafortuna.org/2020/11/22/how-to-detect-cobalt-strike-activity-in-memory-forensics/) 14. [通过指纹识别 Imageload 事件来检测 Cobalt Strike](https://redhead0ntherun.medium.com/detecting-cobalt-strike-by-fingerprinting-imageload-events-6c932185d67c) 15. [APT 攻击剖析与 CobaltStrike Beacon 的编码配置](https://labs.sentinelone.com/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/) 16. [CobaltStrike - beacon.dll:不寻常的 MZ 头](https://tccontre.blogspot.com/2019/11/cobaltstrike-beacondll-your-not.html) 17. [托管在 GitHub 上的恶意软件从 Imgur 图片计算 Cobalt Strike 载荷](https://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-payload-from-imgur-pic/) 18. [在 NetFlow 数据中检测 Cobalt Strike Beacon](https://delaat.net/rp/2019-2020/p29/report.pdf) 19. [用于检测 Cobalt Strike Beacon 的 Volatility 插件](https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html) 20. [使用 JARM 轻松识别互联网上的恶意服务器](https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a) 21. [Cobalt Strike Beacon 分析](https://isc.sans.edu/forums/diary/Quick+Tip+Cobalt+Strike+Beacon+Analysis/26818/) 22. [包含 Pony、Evil Pony、Ursnif 和 Cobalt Strike 的 Hancitor 感染](https://isc.sans.edu/forums/diary/Hancitor+infection+with+Pony+Evil+Pony+Ursnif+and+Cobalt+Strike/25532/) 23. [攻击者利用 CVE-2020-14882 攻击 WebLogic 服务器以安装 Cobalt Strike](https://isc.sans.edu/forums/diary/Attackers+Exploiting+WebLogic+Servers+via+CVE202014882+to+install+Cobalt+Strike/26752/) 24. [隐藏在云端:使用 Amazon API 的 Cobalt Strike Beacon C2](https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/) 25. [识别实际环境中的 Cobalt Strike 团队服务器](https://blog.fox-it.com/2019/02/26/identifying-cobalt-strike-team-servers-in-the-wild/) 26. [多阶段 APT 攻击利用 Malleable C2 功能投放 Cobalt Strike](https://blog.malwarebytes.com/threat-analysis/2020/06/multi-stage-apt-attack-drops-cobalt-strike-using-malleable-c2-feature/) 27. [Cobalt Kitty 行动](http://cdn2.hubspot.net/hubfs/3354902/Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty.pdf) 28. [检测与推进内存中的 .NET 攻击技术](https://www.mdsec.co.uk/2020/06/detecting-and-advancing-in-memory-net-tradecraft/) 29. [分析无文件恶意软件:Cobalt Strike Beacon](https://newtonpaul.com/analysing-fileless-malware-cobalt-strike-beacon/) 30. [IndigoDrop 通过军事主题诱饵传播以投递 Cobalt Strike](https://blog.talosintelligence.com/2020/06/indigodrop-maldocs-cobalt-strike.html) 31. [Cobalt 集团重返哈萨克斯坦](https://research.checkpoint.com/2019/cobalt-group-returns-to-kazakhstan/) 32. [反击退役的 Cobalt Strike:一个遗留漏洞的观察](https://research.nccgroup.com/2020/06/15/striking-back-at-retired-cobalt-strike-a-look-at-a-legacy-vulnerability/) 33. [使用 Cyb3rWard0g 的 Sentinel To-Go 快速部署 Azure Sentinel – 一起来抓 Cobalt Strike!](https://www.blackhillsinfosec.com/azure-sentinel-quick-deploy-with-cyb3rward0gs-sentinel-to-go-lets-catch-cobalt-strike/) 34. [FIN6 使用的 Cobalt Strike Stager](https://malwarelab.eu/posts/fin6-cobalt-strike/) 35. [Malleable C2 配置文件与你](https://haggis-m.medium.com/malleable-c2-profiles-and-you-7c7ab43e7929) 36. [包括 Cobalt Strike 在内的 C2 流量模式](https://marcoramilli.com/2021/01/09/c2-traffic-patterns-personal-notes/) 37. [Cobalt Strike DNS 直连出口并不遥远](https://dtm.uk/cobalt-strike-dns-direct-egress/) 38. [检测暴露的 Cobalt Strike DNS 重定向器](https://labs.f-secure.com/blog/detecting-exposed-cobalt-strike-dns-redirectors) 39. [Cobalt Strike 明文流量示例](https://isc.sans.edu/forums/diary/Example+of+Cleartext+Cobalt+Strike+Traffic+Thanks+Brad/27300/) 40. [Cobaltstrike-Beacons 分析](https://zero.bs/cobaltstrike-beacons-analyzed.html) 41. [通过DNS协议探测Cobalt Strike服务器](https://mp.weixin.qq.com/s/peIpPJLt4NuJI1a31S_qbQ) 42. [使用内存签名检测 Cobalt Strike](https://www.elastic.co/cn/blog/detecting-cobalt-strike-with-memory-signatures) 43. [CobaltStrike通信中host字段的获取](https://zhufan.net/2021/01/05/cobaltstrike%E9%80%9A%E4%BF%A1%E4%B8%ADhost%E5%AD%97%E6%AE%B5%E7%9A%84%E8%8E%B7%E5%8F%96/) 44. [反击CobaltStrike(一) 以假乱真](https://www.anquanke.com/post/id/252332) 45. [某 C2 鸡肋漏洞分析:你的 CS 安全吗?](https://mp.weixin.qq.com/s/SqU7NaFa9du-1r2HX3BJcQ) 46. [来自实际 C2 的 Cobalt Strike Beacon 分析](https://blog.spookysec.net//cs-beacon-analysis/) #### 6. CobaltStrike 视频 1. [使用 Cobalt Strike 的 Beacon 载荷实现可塑的内存指标](https://www.youtube.com/watch?v=93GyP-mEUAw&feature=emb_title) 2. [STAR 网络研讨会:Spooky RYUKy:UNC1878 的归来](https://www.youtube.com/watch?v=BhjQ6zsCVSc) 3. [Excel 4.0 宏分析 - Cobalt Strike Shellcode 注入](https://www.youtube.com/watch?v=XnN_UWfHlNM) 4. [使用 JA3 对所有 SSL 进行画像与检测](https://www.youtube.com/watch?v=oprPu7UIEuk) ### 0x02 C2 配置文件| 类型 | 名称 | 描述 | 流行度 | 语言 | |:---:|:---:|:---:|:---:|:---:| | ALL | [Malleable-C2-Profiles](https://github.com/rsmudge/Malleable-C2-Profiles) | 官方 Malleable C2 配置文件 |  |  | | ALL | [Malleable-C2-Randomizer](https://github.com/bluscreenofjeff/Malleable-C2-Randomizer) | 该脚本通过元语言随机化 Cobalt Strike Malleable C2 配置文件 |  | | | ALL | [malleable-c2](https://github.com/threatexpress/malleable-c2) | Cobalt Strike Malleable C2 设计与参考指南 |  |  | | ALL | [Malleable-C2-Profiles](https://github.com/BC-SECURITY/Malleable-C2-Profiles) | 一个用于 Cobalt Strike 和 Empire 的 Malleable C2 Listener 的配置文件集合。 |  |  | | ALL | [random_c2_profile](https://github.com/threatexpress/random_c2_profile) | 随机 C2 Profile 生成器 |  |  | | ALL | [SourcePoint](https://github.com/Tylous/SourcePoint) | SourcePoint 是一个面向 Cobalt Strike 命令与控制服务器的 C2 profile 生成器,旨在确保规避。 |  |  | | ALL | [C2concealer](https://github.com/FortyNorthSecurity/C2concealer) | C2concealer 是一个命令行工具,可生成用于 Cobalt Strike 的随机化 C2 malleable 配置文件。 |  | | | ALL | [MalleableC2-Profiles](https://github.com/mhaskar/MalleableC2-Profiles) | 一组 Cobalt Strike Malleable C2 配置文件。现在包含 Windows Updates Profile。 |  | | | ALL | [MalleableC2-Profiles](https://github.com/xx0hcd/Malleable-C2-Profiles) | Cobalt Strike - Malleable C2 Profiles。一组在不同项目中使用 Cobalt Strike 的配置文件集合。 |  | | | ALL | [pyMalleableC2](https://github.com/Porchetta-Industries/pyMalleableC2) | 一个用于 Cobalt Strike Malleable C2 配置文件的 Python 解释器,允许你以编程方式解析、修改、构建它们并验证语法。 |  |  | | ALL | [1135-CobaltStrike-ToolKit](https://github.com/1135/1135-CobaltStrike-ToolKit) | Cobalt Strike的Malleable C2配置文件,被设计用来对抗流量分析 |  |  | | ALL | [service_cobaltstrike](https://github.com/wikiZ/service_cobaltstrike) | CobaltStrike 配置文件 |  |  | | ALL | [CobaltNotion](https://github.com/HuskyHacks/CobaltNotion) | 一个衍生研究项目。Cobalt Strike x Notion 合作 2022。 |  |  | | ALL | [Burp2Malleable](https://github.com/CodeXTF2/Burp2Malleable) | 这是我编写的一个快速 Python 实用工具,用于将 burp suite 的 HTTP 请求转换为 Cobalt Strike Malleable C2 配置文件。 |  |  | | ALL | [autoRebind](https://github.com/CrossC2/autoRebind) | 自动将 Malleable C2 profile 解析为 CrossC2 重绑定库源代码。 |  |  | | ALL | [goMalleable](https://github.com/D00Movenok/goMalleable) | 使用 Go 语言编写的 Malleable C2 配置文件解析器和汇编器。 |  |  | | ALL | [Malleable-CS-Profiles](https://github.com/WKL-Sec/Malleable-CS-Profiles) | 一组 Python 工具,用于帮助创建符合 OPSEC 安全的 Cobalt Strike 配置文件。 |  |  | ### 0x03 BOF| 类型 | 名称 | 描述 | 流行度 | 语言 | |:---:|:---:|:---:|:---:|:---:| | 全部 | [BOF_Collection](https://github.com/rvrsh3ll/BOF_Collection) | 各种 Cobalt Strike BOF |  |  | | 全部 | [cobaltstrike-bof-toolset](https://github.com/AttackTeamFamily/cobaltstrike-bof-toolset) | 收集网络中在cobaltstrike中使用的bof工具集。 |  |  | | 全部 | [Situational Awareness BOF](https://github.com/trustedsec/CS-Situational-Awareness-BOF) | 其更大的目标是提供一个代码示例和工作流程,帮助其他人开始制作更多 BOF 文件。[博客](https://www.trustedsec.com/blog/a-developers-introduction-to-beacon-object-files/) |  |  | | 全部 | [bof_helper](https://github.com/dtmsecurity/bof_helper) | Beacon 对象文件 (BOF) 创建助手 |  |  | | 全部 | [BOF-DLL-Inject](https://github.com/tomcarver16/BOF-DLL-Inject) | BOF DLL Inject 是一个自定义的 Beacon 对象文件,它使用手动映射 DLL 注入技术,将 DLL 完全从内存中迁移到进程中。 |  |  | | 全部 | [cobaltstrike_bofs](https://github.com/m57/cobaltstrike_bofs) | 该 BOF 在指定父进程下生成一个您选择的进程,并通过 QueueUserAPC() 注入提供的 shellcode 文件。 |  |  | | 全部 | [BOF-RegSave](https://github.com/EncodeGroup/BOF-RegSave) | 用于 CobaltStrike 的 Beacon 对象文件 (BOF),可获取必要权限并转储 SAM - SYSTEM - SECURITY 注册表项,以便离线解析和哈希提取。 |  |  | | 全部 | [CobaltStrike BOF](https://github.com/Yaxser/CobaltStrike-BOF) | DCOM 横向移动;WMI 横向移动 - Win32_Process 创建;WMI 横向移动 - 事件订阅 |  |  | | 全部 | [BOFs](https://github.com/ajpc500/BOFs) | ETW 修补;API 函数工具;系统调用 Shellcode 注入 |  |  | | 全部 | [Remote Operations BOF](https://github.com/trustedsec/CS-Remote-OPs-BOF) | 此仓库是我们先前发布的 SA 仓库的补充。我们最初的立场是不发布会修改其他系统的工具,只以开箱即用的格式提供信息收集工具。 |  |  | | 全部 | [OperatorsKit](https://github.com/REDMED-X/OperatorsKit) | 该仓库包含一组通过 Beacon 对象文件 (BOF) 与 Cobalt Strike 集成的工具集合。 |  |  | | 开发 | [bof](https://github.com/nccgroup/nccfsas/blob/main/Tools/bof-vs-template/README.md) | 这是一个用于在 Visual Studio 中构建 Cobalt Strike BOF 的模板项目。 |  |  | | 开发 | [Needle_Sift_BOF](https://github.com/EspressoCake/Needle_Sift_BOF) | 使用用户提供的 needle 和文件名实现 Strstr 的 BOF。 |  |  | | 开发 | [Quser-BOF](https://github.com/netero1010/Quser-BOF) | 使用 Windows API 的 Quser Beacon 对象文件实现 |  |  | | 开发 | [BOF.NET](https://github.com/CCob/BOF.NET) | 面向 Cobalt Strike Beacon 对象文件的 .NET 运行时。 |  |  | | 开发 | [beacon-object-file](https://github.com/realoriginal/beacon-object-file) | Mudge 在[此处](https://youtube.com/watch?v=gfYswA_Ronw)描述的格式要求操作者使用 mingw-w64 编译器或 msvc 编译器构建一个 COFF 文件,其中包含一个指示其入口点和底层函数调用的符号名。 |  |  | | 开发 | [InlineWhispers](https://github.com/outflanknl/InlineWhispers) | 演示在 BOF 中使用内联汇编轻松调用系统调用的能力。 |  |  | | 开发 | [WdToggle](https://github.com/outflanknl/WdToggle) | 一个概念验证型 Cobalt Strike Beacon 对象文件,使用直接系统调用启用 WDigest 凭据缓存并绕过 Credential Guard(如果已启用)。 |  |  | | 开发 | [Situational Awareness BOF](https://github.com/trustedsec/CS-Situational-Awareness-BOF) | 此仓库旨在实现两个目的。首先,它提供了一套以 BOF 实现的优秀基础态势感知命令。这使您可以在开始执行可能更具侵入性的命令之前,对主机执行一些检查。 |  |  | | 开发 | [MiniDumpWriteDump](https://github.com/rookuu/BOFs/tree/main/MiniDumpWriteDump) | DbgHelp 的 MiniDumpWriteDump 函数的自定义实现。使用静态系统调用替换 NtReadVirtualMemory 等底层函数。 |  |  | | 开发 | [COFF Loader](https://github.com/trustedsec/COFFLoader) | 这是一个快速而简陋的 COFF 加载器(又称 Beacon 对象文件)。目前可以运行未修改的 BOF,因此可以在没有 CS 代理运行的情况下用于测试。唯一的例外是,与注入相关的 beacon 兼容函数为空。 |  |  | | 开发 | [Self_Deletion_BOF](https://github.com/EspressoCake/Self_Deletion_BOF) | 基于 @jonasLyk 的研究和 @LloydLabs 起草的 PoC 的 BOF 实现 |  |  | | 开发 | [PE Import Enumerator BOF](https://github.com/EspressoCake/DLL_Imports_BOF) | 这是一个用于枚举给定 PE 文件将要加载的 DLL 文件的 BOF。根据参数数量,操作员可以查看预期导入的 DLL 文件列表,或查看某个预期 DLL 的导入函数。 |  |  | | 开发 | [Visual-Studio-BOF-template](https://github.com/securifybv/Visual-Studio-BOF-template) | 用于创建 Cobalt Strike BOF 的 Visual Studio 模板。 |  |  | | 开发 | [BOF-Builder](https://github.com/ceramicskate0/BOF-Builder) | 一个 C# .Net 5.0 项目,用于批量构建 BOF(Beacon 对象文件),前提是它们都位于某个文件夹目录结构中。 |  |  | | 开发 | [ELFLoader](https://github.com/trustedsec/ELFLoader) | 这是一个 ELF 对象的内存加载器/运行器。目标是创建一个单一的 ELF 加载器,可用于在所有 x86_64 和 x86 nix 操作系统上运行后续功能。 |  |  | | 开发 | [Rust BOFs for Cobalt Strike](https://github.com/wumb0/rust_bof) | 这花了我大约 4 天时间,但我最终让它工作了……为 Cobalt Strike BOF 提供 rust core + alloc。这基本上是一个 PoC,但我很乐意看到其他人对它进行尝试并作出贡献。 |  |  | | 开发 | [CoffeeLdr](https://github.com/Cracked5pider/CoffeeLdr) | CoffeeLdr 是所谓 Beacon 对象文件的加载器。该项目可用于在不使用 Cobalt Strike 框架的情况下测试 Beacon 对象文件,也可用于为自定义植入物提供一种执行专为 Cobalt Strike 设计的 BOF 的方式。 |  |  | | 开发 | [HalosGate Processlist Cobalt Strike BOF](https://github.com/boku7/halosgate-ps) | 一个 Cobalt Strike BOF,使用自定义 ASM HalosGate 和 HellsGate 系统调用器返回进程列表。 |  |  | | 开发 | [PPLFaultDumpBOF](https://github.com/trustedsec/PPLFaultDumpBOF) | 将原始的 PPLFault 和附带的 DumpShellcode 组合成一个面向 Cobalt Strike 的 BOF。 |  |  | | 开发 | [Winsocky](https://github.com/WKL-Sec/Winsocky) | 面向 Cobalt Strike 的 Winsocket 实现。用于通过 winsocket 而非传统方式与受害者通信。 |  |  | | 开发 | [bof-vs](https://github.com/Cobalt-Strike/bof-vs) | 一个适用于 Visual Studio 的 Beacon 对象文件 (BOF) 模板。 |  |  | | 辅助 | [Defender Exclusions BOF](https://github.com/EspressoCake/Defender_Exclusions-BOF) | 一个用于确定 Windows Defender 排除项的 BOF。 |  |  | | 辅助 | [ScreenShot-BOF](https://github.com/qwqdanchun/ScreenShot-BOF) | 用于 Cobalt Strike 的 ScreenShot BOF。全内存操作,无需生成/注入进程。 |  |  | | 辅助 | [BofRoast](https://github.com/cube0x0/BofRoast) | 用于对 Active Directory 进行 Roasting 的 Beacon 对象文件仓库。 |  |  | | 辅助 | [EnumCLR.c](https://gist.github.com/G0ldenGunSec/8ca0e853dd5637af2881697f8de6aecc) | 一个 Cobalt Strike BOF,用于识别加载了 CLR 的进程,目标是找出 SpawnTo / 注入候选进程。 |  |  | | 辅助 | [PPEnum](https://github.com/rasta-mouse/PPEnum) | 一个用于读取进程保护级别的简单 BOF。 |  |  | | 辅助 | [secinject](https://github.com/apokryptein/secinject) | 节映射进程注入 (secinject):Cobalt Strike BOF |  | | | 辅助 | [FindObjects-BOF](https://github.com/outflanknl/FindObjects-BOF) | 一个 Cobalt Strike Beacon 对象文件 (BOF) 项目,使用直接系统调用枚举进程中特定的模块或进程句柄。 |  |  | | 辅助 | [Inject-assembly](https://github.com/kyleavery/inject-assembly) | Inject-assembly - 在现有进程中执行 .NET。此工具是 Cobalt Strike 传统 fork 与运行执行方式的替代方案。该加载器可以注入到任何进程中,包括当前 Beacon。长时间运行的程序集会继续运行并将输出发送回 Beacon,类似于 execute-assembly 的行为。 |  |  | | 辅助 | [WhereAmiI](https://github.com/boku7/whereami) | WhereAmiI - 一个 Cobalt Strike Beacon 对象文件 (BOF),使用手写 shellcode 返回进程环境字符串,且不接触任何 DLL。 |  | | 辅助 | [GetWebDAVStatus](https://github.com/G0ldenGunSec/GetWebDAVStatus) | 一个小型项目,通过检查是否存在 DAV RPC SERVICE 命名管道,判断远程系统上是否正在运行 Web Client 服务 (WebDAV)。 |  |  | | 辅助 | [ChromeKeyDump](https://github.com/crypt0p3g/bof-collection/tree/main/ChromeKeyDump) | Chlonium 工具的 BOF 实现,用于转储 Chrome 主密钥并下载 Cookie/登录数据文件 |  |  | | 辅助 | [Sleeper](https://github.com/crypt0p3g/bof-collection/tree/main/Sleeper) | 调用 SetThreadExecutionState 函数以防止主机休眠的 BOF。 |  |  | | 辅助 | [LSASS](https://github.com/pwn1sher/CS-BOFs/tree/main/lsass) | 通过获取快照句柄来转储 Lsass 内存的 Beacon 对象文件。对 LSASS 的快照而非原始 LSASS 本身执行 MiniDumpWriteDump/NtReadVirtualMemory,因此可以规避某些 AV/EDR。 |  |  | | 辅助 | [getsystem](https://github.com/pwn1sher/CS-BOFs/tree/main/get-system) | 通过复制 winlogon 的令牌获取系统权限。 |  |  | | 辅助 | [Silent Lsass Dump](https://github.com/guervild/BOFs) | 静默 Lsass 转储 |  |  | | 辅助 | [unhook-bof](https://github.com/Cobalt-Strike/unhook-bof) | 这是一个用于刷新 DLL 并移除其挂钩的 Beacon 对象文件。 |  |  | | 辅助 | [Beacon Health Check Aggressor Script](https://github.com/Cobalt-Strike/beacon_health_check) | 此 aggressor 脚本使用 beacon 的注释字段来指示 beacon 的健康状态。 |  |  | | 辅助 | [Registry BOF](https://github.com/lpBunny/bof-registry) | 一个用于 Cobalt Strike v4.1+ 的 beacon 对象文件。支持查询、添加和删除本地及远程注册表的键/值。 |  |  | | 辅助 | [InlineExecute-Assembly](https://github.com/anthemtotheego/InlineExecute-Assembly) | InlineExecute-Assembly 是一个概念验证型 Beacon 对象文件 (BOF),允许安全专业人员在进程内执行 .NET 程序集,作为 Cobalt Strike 传统 fork 与运行 execute-assembly 模块的替代方案。 |  |  | | 辅助 | [CredBandit](https://github.com/xforcered/CredBandit) | CredBandit 是一个概念验证型 Beacon 对象文件 (BOF),使用静态 x64 系统调用对进程执行完整的内存转储,并通过您已有的 Beacon 通信信道将结果发回。内存转储通过使用 NTFS 事务完成,这允许我们将转储内容写入内存,并且 MiniDumpWriteDump API 已被替换为 ReactOS 的 MiniDumpWriteDump 实现的改编版本。 |  |  | | 辅助 | [Inject AMSI Bypass](https://github.com/boku7/injectAmsiBypass) | Cobalt Strike Beacon 对象文件 (BOF),通过代码注入绕过远程进程中的 AMSI。 |  |  | | 辅助 | [Firewall_Enumerator_BOF](https://github.com/EspressoCake/Firewall_Walker_BOF) | Cobalt Strike Beacon 对象文件 (BOF),通过代码注入绕过远程进程中的 AMSI。 |  |  | | 辅助 | [Detect-Hooks](https://github.com/anthemtotheego/Detect-Hooks) | 概念验证型 Beacon 对象文件 (BOF),尝试检测 AV/EDR 所设置的用户态挂钩。 |  |  | | 辅助 | [unhook-bof](https://github.com/rsmudge/unhook-bof) | 从 Beacon 进程中移除 API 挂钩。 |  |  | | 辅助 | [whereami](https://github.com/boku7/whereami) | Cobalt Strike "Where Am I?" Beacon 对象文件 |  |  | | 辅助 | [HOLLOW](https://github.com/boku7/HOLLOW) | EarlyBird 进程镂空技术 (BOF) - 以挂起状态生成进程,注入 shellcode,使用 APC 劫持主线程,并执行 shellcode |  |  | | 辅助 | [BOFs](https://github.com/RiccardoAncarani/BOFs) | send_shellcode_via_pipe;cat;wts_enum_remote_processes |  |  | | 辅助 | [SCShell](https://github.com/Mr-Un1k0d3r/SCShell) | SCShell 是一个无文件横向移动工具,依赖于 ChangeServiceConfigA 来运行命令。 |  |  | | 辅助 | [WinRMDLL](https://github.com/mez-0/winrmdll) | 不久前我制作了 CSharpWinRM,效果还不错,但我想认真研究一下 WinRM C++ API。 |  |  | | 辅助 | [LSASS Dumping With Foreign Handles](https://github.com/alfarom256/BOF-ForeignLsass) | 使用外部句柄转储 LSASS |  |  | | 辅助 | [PPLDump BOF](https://github.com/EspressoCake/PPLDump_BOF) | 这是一个功能完备的 BOF,用于转储任意受保护进程 (LSASS)。 |  |  | | 辅助 | [PortBender](https://github.com/praetorian-inc/PortBender) | PortBender 是一个 TCP 端口重定向工具,允许红队操作员将发往一个 TCP 端口(例如 445/TCP)的入站流量重定向到另一个 TCP 端口(例如 8445/TCP)。 |  |  | | 辅助 | [BOF2Shellcode](https://github.com/FalconForceTeam/BOF2shellcode) | 用于将 Cobalt Strike BOF 转换为原始 shellcode 的 POC 工具。 |  |  | | 辅助 | [DLL Hijack Search Order BOF](https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF) | DLL 劫持搜索顺序枚举 BOF |  |  | | 辅助 | [InlineWhispers2](https://github.com/Sh0ckFR/InlineWhispers2) | 通过 Syswhispers2 在 Cobalt Strike 的 Beacon 对象文件 (BOF) 中使用直接系统调用的工具。 |  |  | | 辅助 | [NetUser](https://github.com/lengjibo/NetUser) | 使用windows api添加用户,可用于net无法使用时 |  |  | | 辅助 | [BOF-Nim](https://github.com/byt3bl33d3r/BOF-Nim) | 用Nim语言写BoF |  |  | | 辅助 | [Invoke-Bof](https://github.com/airbus-cert/Invoke-Bof) | 使用 Powershell 加载任意 Beacon 对象文件! |  |  | | 辅助 | [Cobalt-Clip](https://github.com/DallasFR/Cobalt-Clip) | Cobalt-clip 是用于 cobaltstrike 的剪贴板插件,可与剪贴板进行交互。使用它,您可以转储、编辑和监视剪贴板的内容。 |  |  | | 辅助 | [CoffLoader](https://github.com/OtterHacker/CoffLoader) | 在内存中加载并执行 COFF 文件和 Cobalt Strike BOF。 |  |  | | 辅助 | [COFFLoader2](https://github.com/Yaxser/COFFLoader2) | 在内存中加载并执行 COFF 文件和 Cobalt Strike BOF。 |  |  | | 辅助 | [Process Protection Level Enumerator BOF](https://github.com/EspressoCake/Process_Protection_Level_BOF) | 一个仅使用系统调用的 BOF 文件,用于获取进程保护属性,其范围仅限于红队操作员和渗透测试人员通常感兴趣的少数属性。 |  |  | | 辅助 | [Toggle_Token_Privileges_BOF](https://github.com/EspressoCake/Toggle_Token_Privileges_BOF) | 一个(几乎)仅使用系统调用的 BOF 文件,用于在当前进程上下文中添加或删除令牌权限。 |  |  | | 辅助 | [Cobalt Strike BOF - Inject ETW Bypass](https://github.com/boku7/injectEtwBypass) | 通过系统调用 (HellsGate\|HalosGate) 将 ETW 绕过注入远程进程。 |  |  | | 辅助 | [HandleKatz_BOF](https://github.com//EspressoCake/HandleKatz_BOF) | 给你的 Katz 加上 PIC!来看看 HandleKatz,我们的位置无关 Lsass 转储器,它利用克隆句柄、直接系统调用和修改版 minidumpwritedump() 实现功能。 |  |  | | 辅助 | [tgtdelegation](https://github.com/connormcgarr/tgtdelegation) | tgtdelegation 是一个 Beacon 对象文件 (BOF),通过 "TGT 委派技巧" 获取可用的 TGT。 |  |  | | 辅助 | [nanodump](https://github.com/helpsystems/nanodump) | 一个为 LSASS 进程创建 minidump 的 Beacon 对象文件。 |  |  | | 辅助 | [xPipe Cobalt Strike BOF (x64)](https://github.com/boku7/xPipe) | 一个 Cobalt Strike Beacon 对象文件 (BOF),用于列出活动管道并返回其所有者及自主访问控制列表 (DACL) 权限。 |  |  | | 辅助 | [AddUser-Bof](https://github.com/0x3rhy/AddUser-Bof) | 一个添加管理员用户的 Cobalt Strike BOF。 |  |  | | 辅助 | [ServiceMove-BOF](https://github.com/netero1010/ServiceMove-BOF) | 通过滥用 Windows Perception Simulation Service 实现 DLL 劫持的横向移动技术。 |  |  | | 辅助 | [Detect-Hooks](https://github.com/xforcered/Detect-Hooks) | 概念验证型 Beacon 对象文件 (BOF),尝试检测 AV/EDR 所设置的用户态挂钩。 |  |  | | 辅助 | [MemReader BoF](https://github.com/trainr3kt/MemReader_BoF) | MemReader Beacon 对象文件允许您从目标进程内存中搜索和提取特定字符串,并将找到的内容返回到 beacon 输出。 |  |  | | 辅助 | [Readfile BoF](https://github.com/trainr3kt/Readfile_BoF) | 代码不算最漂亮,但简短精炼、直奔主题,允许您将文件内容读取到 beacon 输出。 |  |  | | 辅助 | [ChromiumKeyDump](https://github.com/trainr3kt/Readfile_BoF) | Chlonium 工具的 BOF 实现,用于转储 Chrome/Edge 主密钥并下载 Cookie/登录数据文件 |  |  | | 辅助 | [LdapSignCheck](https://github.com/cube0x0/LdapSignCheck) | 一个 Beacon 对象文件,用于扫描域控制器,检查 LdapEnforceChannelBinding 或 LdapServerIntegrity 是否已被修改以缓解中继攻击。 |  |  | | 辅助 | [DelegationBOF](https://github.com/IcebreakerSecurity/DelegationBOF) | 此工具使用 LDAP 检查域中已知可利用的 Kerberos 委派设置。目前,它支持 RBCD、受约束、带协议转换的受约束以及不受约束委派检查。 |  |  | | 辅助 | [RunOF](https://github.com/nettitude/RunOF) | 一个在 .Net 中运行对象文件(主要是 beacon 对象文件 (BOF))的工具。 |  |  | | 辅助 | [KillDefender_BOF](https://github.com/Octoberfest7/KillDefender_BOF) | pwn1sher 的 KillDefender 的 Beacon 对象文件实现。 |  |  | | 辅助 | [TokenStripBOF](https://github.com/nick-frischkorn/TokenStripBOF) | TokenStrip 是 pwn1sher 的 KillDefender 项目的 Beacon 对象文件实现,通过 InlineWhispers 使用系统调用。 |  |  | | 辅助 | [BOF - RDPHijack](https://github.com/netero1010/RDPHijack-BOF) | 一个 Cobalt Strike Beacon 对象文件 (BOF),使用 WinStationConnect API 执行本地/远程 RDP 会话劫持。 |  |  | | 辅助 | [Koh](https://github.com/GhostPack/Koh) | 一个 Cobalt Strike Beacon 对象文件 (BOF),使用 WinStationConnect API 执行本地/远程 RDP 会话劫持。 |  |  | | 辅助 | [RDPHijack](https://github.com/netero1010/RDPHijack-BOF) | 一个 Cobalt Strike Beacon 对象文件 (BOF),使用 WinStationConnect API 执行本地/远程 RDP 会话劫持。 |  |  | | 辅助 | [KDStab](https://github.com/Octoberfest7/KDStab) | KillDefender 与 Backstab 相结合的 BOF。 |  |  | | 辅助 | [Token Vault BOF for Cobalt Strike](https://github.com/Henkru/cs-token-vault) | 此 Beacon 对象文件 (BOF) 为窃取/复制的 Windows 访问令牌创建内存存储。 |  |  | | 辅助 | [ASRenum](https://github.com/mlcsec/ASRenum-BOF) | 识别 ASR 规则、操作和排除位置。 |  |  | | 辅助 | [ThreadlessInject-BOF](https://github.com/iilegacyyii/ThreadlessInject-BOF) | @_EthicalChaos_ 的 ThreadlessInject 项目的 BOF 实现。一种无需创建线程的新型进程注入技术,于 BSides Cymru 2023 发布。 |  |  | | 辅助 | [Inline-Execute-PE](https://github.com/Octoberfest7/Inline-Execute-PE) | 在 CobaltStrike Beacons 中执行非托管 Windows 可执行文件。这使操作员能够使用许多第三方工具(如 Mimikatz、Dsquery、Sysinternals 工具等),而无需将它们写入磁盘、使用 Donut 之类的工具将它们重新格式化为位置无关代码,或创建新进程来运行它们。 |  |  | | 辅助 | [BOFs](https://github.com/snovvcrash/BOFs) | 订阅 WNF 通知若干秒。&& 对 SCManager SDDL 植入后门。 |  |  | | 辅助 | [DomainPasswordSpray](https://github.com/Hagrid29/BOF-SprayAD) | 使用 Windows API LogonUserSSPI 执行基于 LDAP 或 Kerberos 的密码喷洒。跳过禁用的账户、锁定的账户以及 BadPwdCount 较大的账户(如果指定)。 |  |  | | 辅助 | [BOF-CredUI](https://github.com/Hagrid29/BOF-CredUI) | 通过 CredUIPromptForWindowsCredentials 收集凭据 |  |  | | 辅助 | [Cookie-Graber-BOF](https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF) | 用于提取 WebKit 主密钥以解密用户 cookie 的 C 或 BOF 文件。该 C 代码可用于编译可执行文件或用于 Cobalt Strike 的 bof 脚本。 |  |  | | 辅助 | [ScreenshotBOF](https://github.com/CodeXTF2/ScreenshotBOF) | Cobalt Strike 的一种替代截图功能,使用 WinAPI,不执行 fork & run。截图在内存中下载。 |  |  | | 辅助 | [ScreenshotBOFPlus](https://github.com/baiyies/ScreenshotBOFPlus) | 为 Cobalt Strike 实现无需注入的截图功能。我只对现有代码做了少量优化,并使其支持在 Windows 启用全局缩放时获取完整截图。 |  |  | | 辅助 | [Elevate-System-Trusted-BOF](https://github.com/Mr-Un1k0d3r/Elevate-System-Trusted-BOF) | 此 BOF 可用于将当前 beacon 提升到 SYSTEM 并获取 TrustedInstaller 组权限。模拟通过 SetThreadToken API 完成。 |  |  | | 辅助 | [Hidden Desktop BOF](https://github.com/WKL-Sec/HiddenDesktop) | Hidden Desktop(通常称为 HVNC)是一种工具,允许操作员在用户不知情的情况下与远程桌面会话进行交互。 |  |  | | 辅助 | [DropSpawn](https://github.com/Octoberfest7/DropSpawn_BOF) | DropSpawn 是一个 CobaltStrike BOF,通过一种相对冷门的 DLL 劫持方法生成额外的 Beacon。支持 x86-x86、x64-x64 以及 x86-x64/反之。可作为进程注入的替代方案。 |  |  | | 辅助 | [Nanorobeus](https://github.com/wavvs/nanorobeus) | 用于管理 Kerberos 票据的 COFF 文件 (BOF)。 |  |  | | 辅助 | [SelfDel](https://github.com/seventeenman/SelfDel-BOF) | 通过 SetFileInformationByHandle 删除文件,无论句柄是否正在被使用。 |  |  | | 辅助 | [GetWeChatBOF](https://github.com/pyroxenites/BOFTools/tree/main/GetWeChatBOF) | 用于获取微信信息的BOF测试文件, 仅支持3.9.6.33版本的偏移 |  |  | | 辅助 | [ShadowRDP](https://github.com/c3r3br4t3/ShadowRDP) | 该仓库包含两个应用程序。一个是 Beacon 对象文件,用于获取认证字符串(也称为邀请)。另一个是图形用户界面程序,可在操作员系统上通过 SOCKS 代理运行,以连接远程桌面会话。 |  |  | | 辅助 | [SharpHound4Cobalt](https://github.com/Hypnoze57/SharpHound4Cobalt) | SharpHound 数据(测试文件、json、zip、缓存文件)不会写入磁盘,而只会通过 BOF.NET 库发送到 Cobalt Strike 的下载目录。 |  |  | | 漏洞利用 | [CVE-2020-0796-BOF](https://github.com/rsmudge/CVE-2020-0796-BOF) | SMBGhost 本地提权 |  |  | | 漏洞利用 | [ZeroLogon-BOF](https://github.com/rsmudge/ZeroLogon-BOF) | ZeroLogon |  |  | | 漏洞利用 | [kernel-mii](https://github.com/NorthwaveSecurity/kernel-mii) | 用于利用 CVE-2021-21551 进行内核漏洞利用的 Cobalt Strike (CS) Beacon 对象文件 (BOF) 基础。 |  |  | | 漏洞利用 | [PrivKit](https://github.com/mertdas/PrivKit) | PrivKit 是一个简单的 beacon 对象文件,用于检测 Windows 操作系统上因错误配置导致的权限提升漏洞。 |  |  | | 漏洞利用 | [CVE-2023-36874](https://github.com/Octoberfest7/CVE-2023-36874_BOF) | 关于 针对 CVE-2023-36874 Windows 错误报告 LPE 的武器化 CobaltStrike BOF。 |  |  | | 持久化 | [SPAWN](https://github.com/boku7/spawn) | 一个 Cobalt Strike BOF,生成一个牺牲进程,向其注入 shellcode,并执行载荷。通过使用任意代码防护 (ACG)、BlockDll 和 PPID 欺骗生成牺牲进程,旨在规避 EDR/用户态挂钩。 |  |  | | 持久化 | [PersistBOF](https://github.com/IcebreakerSecurity/PersistBOF) | 一个帮助自动化常见持久化机制的工具。目前支持打印监视器 (SYSTEM)、时间提供程序 (Network Service)、启动文件夹快捷方式劫持 (User) 和联接文件夹 (User)。 |  |  | | 绕过AV | [ClipboardWindow-Inject](https://github.com/BronzeTicket/ClipboardWindow-Inject) | 一个 Beacon 对象文件 (BOF),将 beacon shellcode 注入远程进程,避免使用常见的被监控 API。 |  |  | | 绕过AV | [SigFlip](https://github.com/med0x2e/SigFlip) | SigFlip 是一种修补经过 Authenticode 签名的 PE 文件(exe、dll、sys 等)的工具,修补方式不会影响或破坏现有的 Authenticode 签名。换句话说,您可以通过嵌入数据(例如 shellcode)来更改 PE 文件校验和/哈希,而不会破坏文件签名、完整性校验或 PE 文件功能。 |  |  | | 绕过AV | [BokuLoader](https://github.com/boku7/BokuLoader) | 用汇编语言和 C 编写的 Cobalt Strike 用户定义反射加载器,具有高级规避能力。 |  |  | | 绕过AV | [AddDefenderExclusions](https://github.com/Like0x/AddDefenderExclusions-BOF) | AddDefenderExclusions Beacon 对象文件资源。 |  |  | | 绕过AV | [BOFMask](https://github.com/passthehashbrowns/BOFMask) | 它演示了一种隐蔽运行 BOF 而不让 Beacon 暴露于检测的技术。 |  |  | | 绕过UAC | [Trusted Path UAC Bypass](https://github.com/netero1010/TrustedPath-UACBypass-BOF) | 可信路径 UAC 绕过的 Beacon 对象文件实现。通过使用 DCOM 对象,目标可执行文件将在不涉及 "cmd.exe" 的情况下被调用。 |  |  | | 绕过UAC | [EventViewerUAC_BOF](https://github.com/Octoberfest7/EventViewerUAC_BOF) | 这是由 @orange_8361 发现的 Event Viewer 反序列化 UAC 绕过以及 CsEnox 整理的 POC 的 Beacon 对象文件实现。 |  |  |### 0x04 Aggressor Script| 类型 | 名称 | 描述 | 热度 | 语言 | |:---:|:---:|:---:|:---:|:---:| | BypassAV | [BypassAV](https://github.com/hack2fun/BypassAV) | 用于快速生成免杀的可执行文件 |  |  | | BypassAV | [BypassAV](https://github.com/hack2fun/BypassAV) | 本质上利用的ps2exe.ps1脚本编译为exe,只是不想在命令行里操作,将其写为cna脚本,方便直接快速生成免杀的可执行文件且只有50KB,目前支持exe、ps1文件格式。 |  |  | | BypassAV | [scrun](https://github.com/k8gege/scrun) | BypassAV ShellCode 加载器 (Cobaltstrike/Metasploit) [用法](https://www.cnblogs.com/k8gege/p/11223393.html) |  |  | | BypassAV | [ShellCode_Loader](https://github.com/Axx8/ShellCode_Loader) | Msf&CobaltStrike免杀ShellCode加载器 |  |  | | BypassAV | [beacon-c2-go](https://github.com/wahyuhadi/beacon-c2-go) | beacon-c2-go (Cobaltstrike/Metasploit) |  |  | | BypassAV | [C--Shellcode](https://github.com/OneHone/C--Shellcode) | python ShellCode 加载器 (Cobaltstrike&Metasploit) [用法](http://hone.cool/2019/11/26/%E5%85%8D%E6%9D%80-C-Shellcode%E5%8A%A0%E8%BD%BD%E5%99%A8/) |  |  | | BypassAV | [Doge-Loader](https://github.com/timwhitez/Doge-Loader) | 使用 Golang 编写的 Cobalt Strike ShellCode 加载器 |  |  | | BypassAV | [CS-Loader](https://github.com/Gality369/CS-Loader) | CS免杀,包括python版和C版本的 |  |  | | BypassAV | [CSSG](https://github.com/RCStep/CSSG) | Cobalt Strike Shellcode 生成器。可生成 beacon 无阶段 shellcode,具备暴露退出方式、附加格式化、加密、编码、压缩、多行输出等特性 |  |  | | BypassAV | [Alaris](https://github.com/cribdragg3r/Alaris) | Alaris 是一款新颖且隐蔽的 shellcode 加载器,目前(2021/02/28)能够绕过大多数 EDR 系统。它利用多种已知的 TTP 来保护恶意软件及其执行流程。 |  |  | | BypassAV | [CarbonMonoxide](https://github.com/rkervella/CarbonMonoxide) | EDR 规避 - SwampThing 与 TikiTorch 的组合 |  |  | | BypassAV | [bypassAV-1](https://github.com/jas502n/bypassAV-1) | 条件触发式远控 VT 6/70 免杀国内杀软及defender、卡巴斯基等主流杀软. |  |  | | BypassAV | [ScareCrow](https://github.com/optiv/ScareCrow) | ScareCrow 是一个载荷生成框架,用于生成加载器,以便通过 sideloading(而非注入)方式加载到合法的 Windows 进程中(绕过应用程序白名单控制)。 |  |  | | BypassAV | [Dent](https://github.com/optiv/Dent) | 一个利用 Microsoft WDAPT 传感器漏洞创建基于 COM 的绕过方案的框架。 |  |  | | BypassAV | [PEzor](https://github.com/phra/PEzor) | 开源 PE 加壳器。 |  |  | | BypassAV | [FuckThatPacker](https://github.com/Unknow101/FuckThatPacker) | 一个简单的 Python 加壳器,可轻松绕过 Windows Defender |  |  | | BypassAV | [goShellCodeByPassVT](https://github.com/fcre1938/goShellCodeByPassVT) | Go编译-race参数实现VT全免杀 |  |  | | BypassAV | [HouQing](https://github.com/An0ny-m0us/DesertFox) | 面向红队作战的高级 AV 规避工具 |  |  | | BypassAV | [DesertFox](https://github.com/Hangingsword/HouQing) | 使用Golang实现免杀加载CobaltStrike和Metasploit的shellcode,目前免杀火绒、Avast、腾讯安全管家、360全家桶等主机安全软件。 |  |  | | BypassAV | [DInjector](https://github.com/snovvcrash/DInjector) | 该仓库汇集了使用强大的 D/Invoke API 实现多种 shellcode 注入技术的代码片段 |  |  | | BypassAV | [GoBypass](https://github.com/4ra1n/GoBypass) | Golang免杀马生成工具(该工具仅针对Windows系统) |  |  | | BypassAV | [Bypass-script](https://github.com/sssqp/bypass-script) | 使用 GoBypass 来进行免杀生成 |  |  | | BypassAV | [CobaltWhispers](https://github.com/NVISOsecurity/CobaltWhispers) | CobaltWhispers 是一个 aggressor 脚本,利用一组用于 Cobalt Strike 的 Beacon Object File(BOF)执行进程注入、持久化等操作,并通过直接系统调用绕过 EDR/AV。 |  |  | | BypassAV | [AceLdr](https://github.com/kyleavery/AceLdr) | 用于规避内存扫描器的 Cobalt Strike UDRL。 |  |  | | BypassAV | [SharpTerminator](https://github.com/mertdas/SharpTerminator) | 使用内核驱动终止 AV/EDR 进程 |  |  | | BypassUAC | [UAC-SilentClean](https://github.com/EncodeGroup/UAC-SilentClean) | 该项目实现了一种 DLL 植入技术,可绕过 UAC 的 Always Notify 设置,并在高完整性进程中执行代码。 |  |  | | BypassUAC | [csload.net](https://github.com/YDHCUI/csload.net) | 一个 cobaltStrike Shellcode 加载器,可绕过大多数 AV |  |  | | Dev | [cs-rdll-example](https://github.com/rxwx/cs-rdll-ipc-example) | 这是一个示例代码模式,演示如何在 Cobalt Strike 中使用命名管道与 ReflectiveDll 进行 IPC 通信。 |  |  | | Dev | [Titan](https://github.com/SecIdiot/titan) | Titan:一个用于 Cobalt Strike 的通用用户自定义反射 DLL(UDRL)。 |  |  | | Dev | [GECC](https://github.com/Lz1y/GECC) | 用于 Cobalt Strike 的 Go 语言 External C2 客户端实现。 |  |  | | Dev | [CobaltStrike beacon in rust](https://github.com/b1tg/cobaltstrike-beacon-rust) | 用 Rust 编写的 CobaltStrike beacon。 |  |  | | Recon | [red-team-scripts](https://github.com/threatexpress/red-team-scripts) | 使用 Beacon 内置命令执行一些基础的 Windows 主机枚举 |  |  | | Recon | [Registry-Recon](https://github.com/optiv/Registry-Recon) | 执行系统/AV/EDR 侦察的 Cobalt Strike Aggressor 脚本。 |  |  | | Recon | [aggressor-powerview](https://github.com/tevora-threat/aggressor-powerview) | PowerView 关于页面中列出的所有函数均包含在内,并带有每个函数的全部参数。 [PowerView](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) |  |  | | Recon | [PowerView3-Aggressor](https://github.com/tevora-threat/PowerView3-Aggressor) | 用于 CobaltStrike 的 PowerView Aggressor 脚本 [PowerView](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) |  |  | | Recon | [AggressorScripts](https://github.com/C0axx/AggressorScripts) | Sharphound-Aggressor - 为 SharpHound ingestor 提供的用户菜单 |  |  | | Recon | [ServerScan](https://github.com/Adminisme/ServerScan) | 内网横向信息收集的高并发网络扫描、服务探测工具。 |  |  | | Recon | [TailorScan](https://github.com/uknowsec/TailorScan) | 端口扫描+探测网卡+ms17010探测 |  |  | | Recon | [AggressiveProxy](https://github.com/EncodeGroup/AggressiveProxy) | LetMeOutSharp 会尝试枚举所有可用的代理配置,并使用识别出的代理配置通过 HTTP(s) 与 Cobalt Strike 服务器通信。 |  |  | | Recon | [Spray-AD](https://github.com/outflanknl/Spray-AD) | 一个 Cobalt Strike 工具,用于审计 Active Directory 用户账户是否存在弱密码、常见密码或易于猜测的密码。 |  |  | | Recon | [Ladon](https://github.com/k8gege/Ladon) | Ladon一款用于大型网络渗透的多线程插件化综合扫描神器,含端口扫描、服务识别、网络资产、密码爆破、高危漏洞检测以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描。 |  |  | | Recon | [Ladon for Cobalt Strike](https://github.com/k8gege/Aggressor) | Ladon for Cobalt Strike(巨龙拉冬套件) |  |  | | Recon | [Recon-AD](https://github.com/outflanknl/Recon-AD) | Recon-AD,一个基于 ADSI 和反射 DLL 的 AD 侦察工具 |  |  | | Exploit | [XSS-Fishing2-CS](https://github.com/TheKingOfDuck/XSS-Fishing2-CS) | 鱼儿在cs上线后自动收杆 / 鱼上钩后在 JavaScript 中自动停止钓鱼 |  |  | | Exploit | [XSS-Phishing](https://github.com/timwhitez/XSS-Phishing) | xss钓鱼,cna插件配合php后端收杆 |  |  | | Exploit | [custom_payload_generator](https://github.com/offsecginger/AggressorScripts) | CobaltStrike3.0+ --> 为 Cobalt Strike 的 Beacon 创建多种载荷。当前载荷格式: |  |  | | Exploit | [CrossC2](https://github.com/gloxec/CrossC2) | CrossC2 框架 - 生成 CobaltStrike 的跨平台 beacon |  |  | | Exploit | [CrossC2 Kit](https://github.com/CrossC2/CrossC2Kit) | CrossC2Kit 提供了一些可供用户调用的接口,用于操纵 CrossC2 Beacon 会话,从而扩展 Cobalt Strike 的功能。 |  |  | | Exploit | [Cobaltstrike-MS17-010](https://github.com/phink-team/Cobaltstrike-MS17-010) | ms17-010 漏洞利用工具和扫描器。 |  |  | | Exploit | [AES-PowerShellCode](https://github.com/offsecginger/AES-PowerShellCode) | 我的 Cobalt Strike AES PowerShell 载荷的独立版本。 |  |  | | Exploit | [SweetPotato_CS](https://github.com/Tycx2ry/SweetPotato_CS) | CobaltStrike4.x --> SweetPotato |  |  | | Exploit | [ElevateKit](https://github.com/rsmudge/ElevateKit) | 权限提升漏洞利用 |  |  | | Exploit | [CVE-2018-4878](https://github.com/vysecurity/CVE-2018-4878) | CVE-2018-4878 |  |  | | Exploit | [Aggressor-Scripts](https://github.com/RhinoSecurityLabs/Aggressor-Scripts) | 目前唯一公开的是 UACBypass,其 readme 可在对应文件夹中找到。 |  |  | | Exploit | [CVE_2020_0796_CNA](https://github.com/Rvn0xsy/CVE_2020_0796_CNA) | 基于[ReflectiveDLLInjection](https://github.com/stephenfewer/ReflectiveDLLInjection)实现的本地提权漏洞 |  |  | | Exploit | [DDEAutoCS](https://github.com/p292/DDEAutoCS) | 设置我们的 stage(d) Web Delivery 攻击 |  |  | | Exploit | [geacon](https://github.com/darkr4y/geacon) | 使用 Go 实现 CobaltStrike 的 Beacon(可在 Linux 上使用) |  |  | | Exploit | [geacon_pro](https://github.com//H4de5-7/geacon_pro) | geacon_pro 是基于 geacon 项目、使用 Golang 编写的可绕过杀毒软件的 CobaltStrike Beacon。 |  |  | | Exploit | [geacon_plus](https://github.com/Z3ratu1/geacon_plus) | golang实现的CobaltStrike stageless http(s) beacon,在geacon项目基础上进行了较多扩展 |  |  | | Exploit | [SpoolSystem](https://github.com/nccgroup/nccfsas/blob/main/Tools/spoolsystem/Readme.md) | SpoolSystem 是一个用于 Cobalt Strike 的 CNA 脚本,利用 Print Spooler 命名管道模拟技巧获取 SYSTEM 权限。 |  |  | | Exploit | [CVE-2021-1675_RDL_LPE](https://github.com/mstxq17/CVE-2021-1675_RDL_LPE) | PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR |  |  | | Exploit | [KRBTGS](https://github.com/realoriginal/krbtgs) | KRBTGS 是 Cobalt Strike 的一个后渗透选项,用于获取当前 Beacon 运行或模拟的用户的可用 TGT。该攻击不需要用户密码,仅假设你运行所在的用户处于已加入域的环境中。它会尝试从最强到最弱的加密类型进行猜测。生成的 .ccache 可以转换为 KIRBI 格式,以导入其他 Beacon,或传递给 Impacket 的示例脚本等其他工具集,用于开展你的后渗透工作。 |  |  | | Exploit | [PrintSpoofer-ReflectiveDLL](https://github.com/crisprss/PrintSpoofer) | PrintSpoofer的反射dll实现,结合Cobalt Strike使用 |  |  | | Persistence | [persistence-aggressor-script](https://github.com/ZonkSec/persistence-aggressor-script) | persistence-aggressor-script |  |  | | Persistence | [Peinject_dll](https://github.com/m0ngo0se/Peinject_dll) | 弃用winexec函数,使用shellexecute函数,程序流不在卡顿,达到真正的无感。 |  |  | | Persistence | [TikiTorch](https://github.com/rasta-mouse/TikiTorch) | TikiTorch 遵循相同的概念([CACTUSTORCH](https://github.com/vysecurity/CACTUSTORCH)),但提供了多种进程注入类型,用户可以在编译时指定。 |  |  | | Persistence | [CACTUSTORCH](https://github.com/mdsecactivebreach/CACTUSTORCH) | 一个 JavaScript 和 VBScript shellcode 启动器。它会启动指定二进制文件的 32 位版本,并向其中注入 shellcode。 |  |  | | Persistence | [UploadAndRunFrp](https://github.com/Ch1ngg/AggressorScript-UploadAndRunFrp) | 上传frpc并且运行frpc |  |  | | Persistence | [persistence-aggressor-script](https://github.com/threatexpress/persistence-aggressor-script) | [持久化 Aggressor 脚本](https://zonksec.com/blog/persistence-aggressor-script/) |  |  | | Persistence | [AggressiveGadgetToJScript](https://github.com/EncodeGroup/AggressiveGadgetToJScript) | 使用 GadgetToJScript 技术自动化生成载荷。 |  |  | | Persistence | [FrpProPlugin](https://github.com/mstxq17/FrpProPlugin) | frp0.33修改版,过流量检测,免杀,支持加载远程配置文件可用于cs直接使用的插件 |  |  | | Persistence | [Automatic-permission-maintenance](https://github.com/j5s/Automatic-permission-maintenance) | CobaltStrike 上线自动权限维持插件 |  |  | | Persistence | [cobalt-strike-persistence](https://github.com/Cyri1s/cobalt-strike-persistence) | 使用者通过cobalt strike生成Web Delivery类型的payload,然后加载此脚本可以到达自启动效果 |  |  | | Persistence | [Cobalt_Strike_CNA](https://github.com/yanghaoi/CobaltStrike_CNA) | 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。 |  |  | | Persistence | [CustomKeyboardLayoutPersistence](https://github.com/NtQuerySystemInformation/CustomKeyboardLayoutPersistence) | 使用自定义键盘布局实现代码执行,已在 Windows 11 家庭版 21H2 上测试 |  |  | | Persistence | [SharpEventPersist](https://github.com/improsec/SharpEventPersist) | 通过向事件日志写入/从事件日志读取 shellcode 实现持久化。 |  |  | | Auxiliary | [SharpZippo](https://github.com/OG-Sadpanda/SharpZippo) | 使用 CobaltStrike 的 Execute-Assembly 列出/读取 Zip 文件内容(在内存中且无需解压) |  |  | | Auxiliary | [SharpExcelibur](https://github.com/OG-Sadpanda/SharpExcelibur) | 使用 Cobalt Strike 的 Execute-Assembly 读取 Excel 电子表格(XLS/XLSX) |  |  | | Auxiliary | [SharpSword](https://github.com/OG-Sadpanda/SharpSword) | 使用 Cobalt Strike 的 Execute-Assembly 读取 DOCX 文件内容 |  |  | | Auxiliary | [SharpCat](https://github.com/OG-Sadpanda/SharpCat) | Linux "cat" 命令的 C# 替代品...将文件内容打印到控制台。用于 Cobalt Strike 的 Execute-Assembly |  |  | | Auxiliary | [TabRenamer CNA](https://github.com/EspressoCake/DynamicTabRename) | 这允许你按需以编程方式重命名标签页,并可随意切换你的历史记录。 |  |  | | Auxiliary | [Liquid Snake](https://github.com/RiccardoAncarani/LiquidSnake) | LiquidSnake 是一款允许操作员使用 WMI 事件订阅和 GadgetToJScript 执行无文件横向移动的工具 |  |  | | Auxiliary | [TaskShell](https://github.com/RiccardoAncarani/TaskShell) | TaskShell 计划任务相关自动化操作 |  |  | | Auxiliary | [generate-rotating-beacon](https://github.com/eddiezab/aggressor-scripts/blob/master/generate-rotating-beacon.cna) | 1. 为指定 listener 生成 beacon;2. 将文件托管在指定位置;3. 监控 weblog 以获取指定位置的下载情况; |  |  | | Auxiliary | [ScareCrow-CobaltStrike](https://github.com/GeorgePatsias/ScareCrow-CobaltStrike) | 一个用于 ScareCrow 载荷生成的 Cobalt Strike 脚本。适用于所有 Loader。 |  |  | | Auxiliary | [AggressorScripts](https://github.com/capt-meelo/AggressorScripts) | CreateTicket; Seatbelt; SharpHound |  |  | | Auxiliary | [SharpeningCobaltStrike](https://github.com/cube0x0/SharpeningCobaltStrike) | 在你的 Linux Cobalt Strike 服务器上实时编译 dotnet v35/v40 的 exe/dll 二进制文件,并使用 ConfuserEx 进行混淆。 |  |  | | Auxiliary | [CS_Mail_Tip](https://github.com/0x50j/CS_Mail_Tip) | Cobalt Strike主机上线邮件提醒插件 |  |  | | Auxiliary | [Cobalt_Strike_Bot](https://github.com/r1is/Cobalt_Strike_Bot) | CobaltStrike上线通知,飞书群聊机器人、server酱通知 |  |  | | Auxiliary | [Cobaltstrike-atexec](https://github.com/Rvn0xsy/Cobaltstrike-atexec) | 利用任务计划进行横向,需要与135端口、445端口进行通信 |  |  | | Auxiliary | [Sharp-HackBrowserData](https://github.com/S3cur3Th1sSh1t/Sharp-HackBrowserData) | C#的HackBrowserData工具,方便在cs中直接内存加载 |  |  | | Auxiliary | [HackBrowserData](https://github.com/idiotc4t/Reflective-HackBrowserData) | HackBrowserData的反射模块 |  |  | | Auxiliary | [cobalt_sync](https://github.com/GhostManager/cobalt_sync) | 用于 Ghostwriter 2.0+ 的独立 Cobalt Strike 作战日志记录 Aggressor 脚本 |  |  | | Auxiliary | [samdump](https://github.com/D1sAbl4/samdump) | Cobalt Strike samdump |  |  | | Auxiliary | [CallBackDump](https://github.com/seventeenman/CallBackDump) | 能过卡巴、核晶、defender等杀软的dump lsass进程工具 |  |  | | Auxiliary | [SharpeningCobaltStrike](https://github.com/cube0x0/SharpeningCobaltStrike) | 在你的 Linux Cobalt Strike 服务器上实时编译 dotnet v35/v40 的 exe/dll 二进制文件,并使用 ConfuserEx 进行混淆。 |  |  | | Auxiliary | [SharpCompile](https://github.com/SpiderLabs/SharpCompile) | SharpCompile 是一个用于 Cobalt Strike 的 aggressor 脚本,允许你实时编译和执行 C# 代码。 |  |  | | Auxiliary | [Quickrundown](https://github.com/icebearfriend/Quickrundown) | 使用 QRD,操作员可以通过颜色和对所显示进程的备注,快速判断主机上哪些进程是已知的、哪些是未知的。 |  |  | | Auxiliary | [NetUser](https://github.com/bopin2020/NetUser) | 该工具通过 Window API 实现 "net user" 功能。我制作此工具用于与 Cobalt Strike 的 execute-assembly 配合使用,所以可以内存加载添加用户 |  |  | | Auxiliary | [FileSearch](https://github.com/c1y2m3/FileSearch) | C++枚举磁盘列表、遍历指定盘搜索特定类型文件包括反射DLL版本。 |  |  | | Auxiliary | [Phant0m_cobaltstrike](https://github.com/p292/Phant0m_cobaltstrike) | 该脚本遍历事件日志服务进程(特定的 svchost.exe)的线程堆栈,识别事件日志线程并将其杀死。这样系统将无法收集日志,同时事件日志服务看起来仍在运行。 |  |  | | Auxiliary | [NoPowerShell](https://github.com/bitsadmin/nopowershell) | NoPowerShell 是一个用 C# 实现的工具,支持执行类似 PowerShell 的命令,同时对任何 PowerShell 日志记录机制保持不可见。 |  |  | | Auxiliary | [EventLogMaster](https://github.com/QAX-A-Team/EventLogMaster) | RDP 事件日志主控 |  |  | | Auxiliary | [ANGRYPUPPY](https://github.com/vysecurity/ANGRYPUPPY) | 用于 Cobalt Strike 的 Bloodhound 攻击路径执行 |  |  | | Auxiliary | [CobaltStrike_Script_Wechat_Push](https://github.com/a1ices/CobaltStrike_Script_Wechat_Push) | 上线微信提醒的插件,通过微信Server酱提醒 |  |  | | Auxiliary | [CS-Aggressor-Scripts](https://github.com/secgroundzero/CS-Aggressor-Scripts) | Slack 和 webhooks 提醒 |  |  | | Auxiliary | [Aggressor-Scripts](https://github.com/skyleronken/Aggressor-Scripts) | 对目标上的 powershell 进行探测(在对应的目标上检测powershell的相关信息) |  |  | | Auxiliary | [cs-magik](https://github.com/tomsteele/cs-magik) | 为 Cobalt Strike 实现了一个基于 Redis 的事件通道和任务队列。 |  |  | | Auxiliary | [GetClipboard](https://github.com/0x3rhy/GetClipboard) | 用于获取剪贴板内容的 Cobalt Strike 反射 DLL。代码基本上来自 ReflectiveDLLInjection |  |  | | Auxiliary | [AggressorScripts](https://github.com/zer0yu/AggressorScripts) | 查看进程的时候讲av进程标注为红色 |  |  | | Auxiliary | [Beaconator](https://github.com/capt-meelo/Beaconator) | Beaconator 是一个用于 Cobalt Strike 的 aggressor 脚本,用于生成原始的无阶段(stageless)shellcode,并使用 PEzor 对生成的 shellcode 进行打包。 |  |  | | Auxiliary | [Raven](https://github.com/xorrior/raven) | 用于 WebSocket 的 CobaltStrike External C2 |  |  | | Auxiliary | [CobaltStrikeParser](https://github.com/Sentinel-One/CobaltStrikeParser) | 用于解析 CobaltStrike Beacon 配置的 Python 解析器 |  |  | | Auxiliary | [fakelogonscreen](https://github.com/bitsadmin/fakelogonscreen) | FakeLogonScreen 是一个伪造 Windows 登录屏幕以获取用户密码的实用工具。 |  |  | | Auxiliary | [SyncDog](https://github.com/Lz1y/SyncDog) | 使 BloodHound 与 CobaltStrike 保持同步。 |  |  | | Auxiliary | [360SafeBrowsergetpass](https://github.com/hayasec/360SafeBrowsergetpass) | 一键辅助抓取360安全浏览器密码的CobaltStrike脚本,通过下载浏览器数据库、记录密钥来离线解密浏览器密码。 |  |  | | Auxiliary | [SharpDecryptPwd](https://github.com/uknowsec/SharpDecryptPwd) | 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。 |  |  | | Auxiliary | [List-GitHubAssembly](https://github.com/mdsecactivebreach/Execute-GithubAssembly-Aggressor) | 从配置的 GitHub 仓库获取可用 artifact 列表。 |  |  | | Auxiliary | [ExecuteAssembly](https://github.com/med0x2e/ExecuteAssembly) | ExecuteAssembly 是 CS execute-assembly 的一个替代方案,使用 C/C++ 构建。它可以通过以下方式加载/注入 .NET 程序集:复用宿主(spawnto)进程已加载的 CLR 模块/AppDomainManager、踩踏 Loader/.NET 程序集的 PE DOS 头、对 .NET 相关模块进行 Unlink、绕过 ETW+AMSI、通过 NT 静态系统调用(x64)规避 EDR 钩子,以及通过 superfasthash 哈希算法动态解析 API 来隐藏导入。 |  |  | | Auxiliary | [aggrokatz](https://github.com/sec-consult/aggrokatz) | aggrokatz 是 CobaltStrike 的一个 Aggressor 插件扩展,使 pypykatz 能够远程与 beacon 交互。 |  |  | | Auxiliary | [Zipper](https://github.com/outflanknl/Zipper) | 这个 CobaltStrike 工具允许红队压缩来自本地和 UNC 路径的文件和文件夹。在需要外传大文件或文件夹的情况下,这会很有用。压缩文件或文件夹后,会在用户临时文件夹中创建一个随机命名的 zip 文件。 |  |  | | Auxiliary | [CS-ServerChan](https://github.com/lintstar/CS-ServerChan) | 通过 CobaltStike 服务端 / 客户端 挂载脚本,将上线主机信息通过 Server 酱通知到微信 |  |  | | Auxiliary | [CS-PushPlus](https://github.com/lintstar/CS-PushPlus) | 使用免费且支持微信模板消息推送的 PushPlus 进行上线主机提醒 |  |  | | Auxiliary | [HelpColor](https://github.com/outflanknl/HelpColor) | 列出可用 Cobalt Strike beacon 命令并根据其类型着色显示的 Aggressor 脚本 |  |  | | Auxiliary | [CobaltStrike Helpmsg CNA](https://github.com/lpBunny/cobaltstrike-helpmsg-cna) | 该 cna 包含 Win32 错误代码、HRESULT 定义和 NTSTATUS 定义的错误消息。对于那些在无法访问 net.exe 程序的 linux/mac 客户端上操作的人来说,这个 cna 会很有用,或者作为一种无需 Google 搜索即可快速查看 hresult/ntstatus 代码的方式。 |  |  | | Auxiliary | [YouMayPasser](https://github.com/waldo-irc/YouMayPasser) | 稳定的 PeSieve 绕过和稳定的 Moneta 绕过。 |  |  | | Auxiliary | [Sync Downloads](https://github.com/EspressoCake/BeaconDownloadSync) | 这是一个用于从数据模型中的 Cobalt Strike Downloads 条目同步文件的精细控制机制 |  |  | | Auxiliary | [Headless Strike](https://github.com/CodeXTF2/cobaltstrike-headless) | 一个 Aggressor 脚本,可将 headless aggressor 客户端转变为(基本)可用的 Cobalt Strike 客户端。 |  |  | | Auxiliary | [Headless Strike](https://github.com/F3eev/SharkExec) | 内网渗透\红队工具\C#内存加载\cobaltstrike |  |  | | Auxiliary | [Cohab_Processes](https://github.com/Octoberfest7/Cohab_Processes) | 一个帮助红队识别主机上外来进程的小型 Aggressor 脚本 |  |  | | Auxiliary | [EnumStrike](https://github.com/DallasFR/EnumStrike) | 用于自动化主机和域枚举的 Cobalt Strike Aggressor 脚本。 |  |  | | Synthesis | [AM0N-Eye](https://github.com/S3N4T0R-0X0/AMON-Eye) | AM0N-Eye 汇集了一组专为 CobaltStrike 编写的最重要脚本,其余文件(如 de)用于修改颜色和图像。 |  |  | | Synthesis | [aggressor_snippets](https://github.com/Octoberfest7/aggressor_snippets) | 一些不值得单独建仓库的零散小型 Aggressor 代码片段的集合 |  |  | | Synthesis | [Erebus](https://github.com/DeEpinGh0st/Erebus) | CobaltStrike4.x --> Erebus CobaltStrike后渗透测试插件 |  |  | | Synthesis | [CSplugins](https://github.com/SeaOf0/CSplugins) | CobaltStrike后渗透测试插件集合 |  |  | | Synthesis | [Cobalt-Strike-Aggressor-Scripts](https://github.com/timwhitez/Cobalt-Strike-Aggressor-Scripts) | CobaltStrike后渗透测试插件集合 [用法](https://github.com/timwhitez/Cobalt-Strike-Aggressor-Scripts/wiki/Usage) |  |  | | Synthesis | [AggressorScripts](https://github.com/bluscreenofjeff/AggressorScripts) | 用于 Cobalt Strike 3.0+ 的 Aggressor 脚本 |  |  | | Synthesis | [RedTeamTools](https://github.com/lengjibo/RedTeamTools) | 用于 Cobalt Strike 的 RedTeamTools |  |  | | Synthesis | [cobalt-arsenal](https://github.com/mgeeky/cobalt-arsenal) | 用于 Cobalt Strike 4.0+ 的 Aggressor 脚本 |  |  | | Synthesis | [MoveKit](https://github.com/0xthirteen/MoveKit) | 该 aggressor 脚本通过读取特定执行类型的模板文件来处理载荷创建。[介绍](https://www.4hou.com/posts/jO1y) |  |  | | Synthesis | [StayKit](https://github.com/0xthirteen/StayKit) | 该 aggressor 脚本通过读取特定执行类型的模板文件来处理载荷创建。[介绍](https://www.4hou.com/posts/jO1y) |  |  | | Synthesis | [AggressorScripts](https://github.com/ramen0x3f/AggressorScripts) | AggressorScripts |  |  | | Synthesis | [AggressorScripts](https://github.com/harleyQu1nn/AggressorScripts) | 从多个来源收集的、用于 Cobalt Strike 3.0+ 的 Aggressor 脚本集合 |  |  | | Synthesis | [AggressorScripts](https://github.com/ramen0x3f/AggressorScripts) | AggressorScripts |  |  | | Synthesis | [Aggressor-VYSEC](https://github.com/vysecurity/Aggressor-VYSEC) | 包含大量 CobaltStrike Aggressor 脚本 |  |  | | Synthesis | [AggressorAssessor](https://github.com/FortyNorthSecurity/AggressorAssessor) | AggressorAssessor |  |  | | Synthesis | [AggressorAssessor](https://github.com/FortyNorthSecurity/AggressorAssessor) | AggressorAssessor |  |  | | Synthesis | [aggressor-scripts](https://github.com/threatexpress/aggressor-scripts) | Cobalt Strike Aggressor 脚本集合 |  |  | | Synthesis | [梼杌](https://github.com/pandasec888/taowu-cobalt-strike) | 基于cobalt strike平台的红队自动化框架 |  |  | | Synthesis | [Aggressor-scripts](https://github.com/Und3rf10w/Aggressor-scripts) | 这只是我为 Cobalt Strike 3.x 编写的 Aggressor 脚本的随机集合。(其中有一个debug脚本比较好用) |  |  | | Synthesis | [Aggressor-Script](https://github.com/rasta-mouse/Aggressor-Script) | 用于 Cobalt Strike 的 Aggressor 脚本集合(主要包含了提权和权限维持脚本) |  |  | | Synthesis | [Aggressor-Script](https://github.com/QAX-A-Team/CobaltStrike-Toolset) | Aggressor 脚本、Kit、Malleable C2 Profiles、External C2 等 |  |  | | Synthesis | [aggressor_scripts_collection](https://github.com/michalkoczwara/aggressor_scripts_collection) | 收集了来自各路大神的各种 Cobalt Strike Aggressor 脚本。会持续更新本仓库,并向每个人致谢。 |  |  | | Synthesis | [CobaltStrike-ToolKit](https://github.com/killswitch-GUI/CobaltStrike-ToolKit) | googlesearch.profile 以及与 AD 相关的脚本。 |  |  | | Synthesis | [Arsenal](https://github.com/Cliov/Arsenal) | Cobalt Strike 3.13 Arsenal Kit |  |  | | Synthesis | [cobalt-arsenal](https://github.com/mgeeky/cobalt-arsenal) | 我收集的经过实战检验的、用于 Cobalt Strike 4.0+ 的 Aggressor 脚本 |  |  | | Synthesis | [aggressor_scripts](https://github.com/001SPARTaN/aggressor_scripts) | 一组有用的 Cobalt Strike 脚本集合。(powershell.cna;bot.cna;dcom_lateral_movement.cna;ElevateKit) |  |  | | Synthesis | [aggressor](https://github.com/gaudard/scripts/tree/master/red-team/aggressor) | 使用 netsh 创建隧道;将默认重定向改为 bit.ly 跳转到麦当劳;使用 powershell 终止父进程; |  |  | | Synthesis | [CobaltStrikeCNA](https://github.com/branthale/CobaltStrikeCNA) | 一组脚本集合 - 来自不同来源 - 详见脚本。 |  |  | | Synthesis | [AggressorScripts](https://github.com/oldb00t/AggressorScripts) | 在 beacon 中高亮显示 ps 命令选中的进程;向 beacon 加载各种别名;为后续使用的脚本设置一些默认值.. |  |  | | Synthesis | [AggressorAssessor](https://github.com/FortyNorthSecurity/AggressorAssessor) | 从C2生成到横向移动的全辅助脚本套件 |  |  | | Synthesis | [AggressorCollection](https://github.com/invokethreatguy/AggressorCollection) | 很棒的 Cobalt Strike Aggressor 脚本集合。所有功劳归功于原作者 |  |  | | Synthesis | [Cobaltstrike-Aggressor-Scripts-Collection](https://github.com/bytecod3r/Cobaltstrike-Aggressor-Scripts-Collection) | 经过测试的 CobaltStrike aggressor 脚本集合。 |  |  | | Synthesis | [aggressorScripts](https://github.com/Matrix20085/aggressorScripts) | 为懒人准备的 CobaltStrike AggressorScripts |  |  | | Synthesis | [Aggressor_Scripts](https://github.com/EspressoCake/Aggressor_Scripts) | 我为作战目的编写的 Aggressor/Sleep 脚本汇编。 |  |  | | Synthesis | [cobalt_strike_extension_kit](https://github.com/josephkingstone/cobalt_strike_extension_kit) | 集成了SharpHound,SharpRDP,SharpWMI等在内的各种内网工具,使用AggressorScripts构建workflow |  |  | | Synthesis | [cobaltstrike](https://github.com/wafinfo/cobaltstrike) | 具备域管理员定位、域信息收集、权限维持、内网扫描、数据库hash dump、Everything内网搜索文件等功能的插件集合 |  |  | | Synthesis | [365CobaltStrike](https://github.com/0e0w/CobaltStrike) | 兼容CobaltStrike4.0的插件集合 |  |  | | Synthesis | [Cobalt-Strike](https://github.com/Mikasazero/Cobalt-Strike) | 内容有横向移动、密码抓取、权限提升、权限维持等,尽可能将内网渗透中常用到的东西整理一下,方便使用 |  |  | | Synthesis | [CSPlugins](https://github.com/Al1ex/CSPlugins) | 一个对Cobaltstrike第三方插件进行收集的项目,持续更新。 |  |  | | Synthesis | [CobaltStrike-xor](https://github.com/WBGlIl/CobaltStrike-file) | 第三方 --> vnc_x86_dll and vnc_x64_dll |  |  | | Synthesis | [Z1-AggressorScripts](https://github.com/z1un/Z1-AggressorScripts) | 适用于Cobalt Strike 3.x & 4.x 的内网渗透插件集合 |  |  | | Synthesis | [csplugin](https://github.com/422926799/csplugin) | 导入PowerView脚本,和常见的功能使用 |  |  | | Synthesis | [CSplugins](https://github.com/SeaOf0/CSplugins) | 涉及工作目录、信息收集、凭据获取、权限维持、权限提升、用户相关、RDP相关、防火墙相关、域渗透、powershell相关、内网穿透、内网探测、远程文件下载、痕迹清除的综合型插件系统 |  |  | | Synthesis | [LSTAR](https://github.com/lintstar/LSTAR) | 本着简化 CS 右键和方便自己集成的目的,对 Reference 里的项目进行了缝合以及二次开 (抄) 发 (袭)并添加了虚拟机/AV 检测、主机相关密码抓取、 Cxk 限时免杀的 Mimikatz 和 Adduser 等功能 |  |  | | Synthesis | [SharpUtils](https://github.com/breakid/SharpUtils) | 一组旨在与 Cobalt Strike 的 execute-assembly 配合使用的 C# 实用工具集合。 |  |  | | Synthesis | [SharpToolsAggressor](https://github.com/uknowsec/SharpToolsAggressor) | 内网渗透中常用的c#程序整合成cs脚本,直接内存加载。持续更新~ |  |  | | Synthesis | [C.Ex](https://github.com/Sifter-Ex/cPlug) | CobaltStrike 插件,用于在 Sifter 内部(本地或远程)启动和使用 Cobalt Strike |  |  | | Synthesis | [OLa](https://github.com/d3ckx1/OLa) | 一款CS后渗透模块插件,让大家使用一款插件就够了,本插件集大家之所长### 0x05 相关工具 | 类型 | 名称 | 描述 | 热度 | 语言 | |:---:|:---:|:---:|:---:|:---:| | 反CobaltStrike | [cobaltstrike_brute](https://github.com/isafe/cobaltstrike_brute) | Cobalt Strike 团队服务器密码暴力破解器 |  |  | | 反CobaltStrike | [Dissecting Cobalt Strike using Python](https://github.com/fox-it/dissect.cobaltstrike) | dissect.cobaltstrike 是一个 Python 库,用于剖析和解析 Cobalt Strike 相关数据,例如 beacon 载荷和 Malleable C2 Profiles。 |  |  | | 反CobaltStrike | [CobaltSpam](https://github.com/hariomenkel/CobaltSpam) | Cobalt Strike 团队服务器密码暴力破解器 |  |  | | 反CobaltStrike | [CobaltStrikeDos](https://github.com/JamVayne/CobaltStrikeDos) | CVE-2021-36798 EXP:Cobalt Strike < 4.4 拒绝服务 |  |  | | 反CobaltStrike | [CS_mock](https://github.com/burpheart/CS_mock) | 模拟cobalt strike beacon上线包 |  |  | | 反CobaltStrike | [CS_fakesubmit](https://github.com/LiAoRJ/CS_fakesubmit) | 一个可以伪装上线Cobaltstrike的脚本 |  |  | | 反CobaltStrike | [CobaltStrikeScan](https://github.com/LiAoRJ/CS_fakesubmit) | 扫描文件或进程内存,查找 Cobalt Strike beacon 并解析其配置。 |  |  | | 反CobaltStrike | [grab_beacon_config](https://github.com/whickey-r7/grab_beacon_config) | 用于扫描并获取 CobaltStrike Beacon 配置的简单 PoC 脚本。 |  |  | | 反CobaltStrike | [C2-JARM](https://github.com/cedowens/C2-JARM) | 通过ssl实现所产生的JARM hash来识别不同的c2,例如CobaltStrike |  |  | | 反CobaltStrike | [JARM](https://github.com/salesforce/jarm) | JARM 指纹扫描器 |  |  | | 反CobaltStrike | [DetectCobaltStomp](https://github.com/slaeryan/DetectCobaltStomp) | 一个快速(甚至可能有点粗糙!)的 PoC 工具,用于以中高置信度检测 Cobalt Strike 实现的 Module Stomping。 |  |  | --- [了解更多](https://github.com/zer0yu/awesome-cobaltstrike)