Posts

Showing posts with the label Cobalt Strike

Redelk - Tardily Deployable Tool For Cherry-Red Teams Used For Tracking Too Alarming Nigh Blueish Squad Activities Equally Good Equally Improve Usability Inwards Long Term Operations

Image
Red Team's SIEM - slow deployable tool for Red Teams used for tracking together with alarming nearly Blue Team activities every bit good every bit improve usability for the Red Team inward long term operations. Initial world free at BruCON 2018: Video: https://www.youtube.com/watch?v=OjtftdPts4g Presentation slides: https://github.com/outflanknl/Presentations/blob/master/MirrorOnTheWall_BruCon2018_UsingBlueTeamTechniquesinRedTeamOps_Bergman-Smeets_FINAL.pdf Goal of the project Short: a Red Team's SIEM. Longer: a Red Team's SIEM that serves 3 goals: Enhanced usability together with overview for the cerise squad operators past times creating a primal place where all relevant operational logs from multiple teamservers are collected together with enriched. This is peachy for historic searching inside the performance every bit good every bit giving a read-only persuasion on the performance (e.g. for the White Team). Especially useful for multi-scenario, multi-tea...

Chkdfront - Cheque Domain Fronting

Image
chkdfront checks if your domain fronting is working yesteryear testing the targeted domain (fronted domain) against your domain front end domain. Features Checking your domain fronted against the domain front. Searching an expected string inward the answer to betoken success. Showing troubleshooting suggestions when a examination fails based on the failure natural. Inspecting the HTTP asking together with answer when a examination fails. (optionally if succeeded). Troubleshooting alongside diverse checks (ping, HTTP, nslookup) when a examination fails. (optionally if succeeded). Support testing though proxy. Demo Please banking concern represent the demo https://asciinema.org/a/nA9wBiuSDLDH9SunQ8GxKT2ra Installation $ jewel install chkdfront Usage Help menu: -f, --front-target URL Fronted target domain or URL. e.g. images.businessweek.com -d, --domain-front DOMAIN DomainFront domain. ...

Evil Clippy - A Cross-Platform Assistant For Creating Malicious Ms Purpose Documents

Image
Influenza A virus subtype H5N1 cross-platform assistant for creating malicious MS Office documents. Can enshroud VBA macros, stomp VBA code (via P-Code) too confuse macro analysis tools. Runs on Linux, OSX too Windows. Current features Hide VBA macros from the GUI editor VBA stomping (P-code abuse) Fool analyst tools Serve VBA stomped templates via HTTP Set/Remove VBA Project Locked/Unviewable Protection If yous accept no thought what all of this is, cheque out the next resources first: MS Office Magic Show presentation at Derbycon 2018 VBA stomping resources past times the Walmart safety team Pcodedmp past times Dr. Bontchev How effective is this? At the fourth dimension of writing, this tool is capable of getting a default Cobalt Strike macro to bypass all major antivirus products too only about maldoc analysis tools (by using VBA stomping inward combination amongst random module names). Technology Evil Clippy uses the OpenMCDF library to manipulate MS Of...