|
本次更新内容如下:
8 Apr 15 - Cobalt Strike 2.4
--------
+ Added dllinject to Beacon. Injects a Reflective DLL into a process
- Sped up rendering of graph view on Windows and MacOS X.
+ Beacon now has a concept for long-running post exploitation jobs.
Use the jobs command to list jobs. Use the jobkill command to kill
a job. The keystroke logger, PowerShell tasks, and Command Shell tasks
now use this mechanism.
+ Keystroke logger now injects into an x86 or x64 process of your
choosing and reports keystrokes back to you.
+ Added hashdump command to Beacon
+ Integrated mimikatz into Beacon. Use wdigest to dump plaintext creds.
Use mimikatz [command] [args] to run an arbitrary mimikatz command.
+ Fixed Beacon's internal types to allow working with large PIDs.
+ Revised VNC client -> server staging and connection process to
eliminate a layer of unnecessary tunneling and improve reliability.
+ Payload names in Listener dialog are now in alphabetical order. This
will mess with muscle memory for some of us. It's for the best though
+ Added foreign listeners. These listeners are aliases for Meterpreter
or Beacon handlers managed elsewhere.
+ Added a sanity check for when an Applet Kit script can't find its
jar resource.
+ Added PowerApplet to the Cobalt Strike Arsenal. This alternate
implementation of the Cobalt Strike Applet Attacks uses PowerShell
to inject a payload into memory.
- Made YAML parser more liberal with punctuation characters.
+ Fixed a malleable c2 bug that affected safebrowsing.profile
+ Improved c2lint utility with a few new checks and enhanced checks
+ Added another A/V bypass technique to the Artifact Kit.
+ Tweaked artifacts Cobalt Strike generates
+ Performed normal client-side database maintenance
下载地址:http://pan.baidu.com/s/1i35VYPB |
|