Skip to content

Added a few checks based on BOF.NET (SeatBelt, Rubeus, SharPersis…#1

Open
m-nigma wants to merge 1 commit intoTH3xACE:mainfrom
m-nigma:main
Open

Added a few checks based on BOF.NET (SeatBelt, Rubeus, SharPersis…#1
m-nigma wants to merge 1 commit intoTH3xACE:mainfrom
m-nigma:main

Conversation

@m-nigma
Copy link
Copy Markdown

@m-nigma m-nigma commented Jun 22, 2022

Hi @TH3xACE,

I've created a few checks for your framework based on a few publicly available tools.

The following tools need to be imported into the Cobalt Strike client in order to perform some of the checks:

  1. BOF.NET fork
  2. chromiumkeydump BOF:
  3. Nanodump BOF
    The following projects need to be compiled and binaries should be placed next to the "edr-tests.cna" file within "checks" directory:
  4. Rubeus
  5. SharPersist
  6. SeatBelt

If you encounter any issues please let me know. You can contact me via Twitter @mnigma.

@sec13b
Copy link
Copy Markdown

sec13b commented Feb 24, 2024

i dont think work

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants