EDR-Test
EDR-Test copied to clipboard
Added a few checks based on BOF.NET (SeatBelt, Rubeus, SharPersis…
Hi @TH3xACE,
I've created a few checks for your framework based on a few publicly available tools.
The following tools need to be imported into the Cobalt Strike client in order to perform some of the checks:
- BOF.NET fork
- chromiumkeydump BOF:
- Nanodump BOF The following projects need to be compiled and binaries should be placed next to the "edr-tests.cna" file within "checks" directory:
- Rubeus
- SharPersist
- SeatBelt
If you encounter any issues please let me know. You can contact me via Twitter @mnigma.
i dont think work