0x00 前言

收集到的网络上的 CS 文章,包含部署隐藏,上线提醒等等技巧

教程

Fofa

1
cert="73:6B:5E:DB:CF:C9:19:1D:5B:D0:1F:8C:E3:AB:56:38:18:9F:02:4F"

0x01 隐藏

https://mp.weixin.qq.com/s/2EQ6-NjUDG90Ge5Ml_1X_Q

https://mp.weixin.qq.com/s/V6huSfYfl355HXgUnflAOA

https://mp.weixin.qq.com/s/ssi71BzvLBnuR8dZj-9Ccg

0x02 上线

https://mp.weixin.qq.com/s/m88skTT0xdooLqSGP4BXAQ

https://mp.weixin.qq.com/s/gYyB-vNskvXVubV9s_Dzgw

上线提醒

https://github.com/lintstar/CS-PushPlus

绕过 vultr 特征检测

https://www.wangan.com/p/7fy74727d2f60d4f

http://www.javaheidong.com/blog/article/344451/46db0472067ab95e51f2/

0x03 插件

插件

Cobalt Strike 可以使用 AggressorScripts 脚本来加强自身,能够扩展菜单栏,Beacon 命令行,提权脚本等

0x04 文章 & Reference

0x05 实验

https://github.com/ffffffff0x/1earn/blob/master/1earn/Security/RedTeam/%E5%90%8E%E6%B8%97%E9%80%8F/%E5%AE%9E%E9%AA%8C/C2%E5%AE%9E%E9%AA%8C.md#%E9%87%8D%E5%AE%9A%E5%90%91

0x0 下载

https://www.upload.ee/files/13456591/Cobalt_Strike_4.4__August_04__2021_.7z.html