GithubHelp home page GithubHelp logo

handlekatz_bof's Introduction

HandleKatz_BOF

What is this?

This is a (mostly complete) port of the functionality presented by @thefLink and Code White GmbH. You guys deserve a large amount of thanks for taking the time to present your research!

Why?

This was a personal question to answer if this would work within Cobalt Strike, and if so, how?

What are the options this currently supports

  • There are two required parameters, a PID and a filepath to write the dumpfile to. (e.g. handlekatz 780 C:\Users\User\Desktop\obfuscated.dmp)

How do I run this?

  1. In this case, you have two options:
    1. Use the existing, compiled object file, located in the dist directory (AKA proceed to major step two)
    2. Compile from source via the Makefile
      1. cd src
      2. make clean
      3. make
  2. Load the Aggressor file, in the Script Manager, located in the dist directory

Any known downsides?

  • We're still using the Win32 API and Dynamic Function Resolution. This is for you to determine as far as "risk"
  • You may attempt to incur a privileged action without sufficient requisite permissions. I can't keep you from burning your hand.

Where can we go from here?

  • Implement the one remaining overt Win32 API call invoked with the Dynamic Function Resolution syntax (VirtualAlloc) to be a call to NtAllocateVirtualMemory. I've included the necessary header(s) with implementation in syscalls.h. Enjoy! :)

handlekatz_bof's People

Contributors

espressocake avatar

Stargazers

 avatar AVA avatar  avatar secdude avatar  avatar  avatar  avatar Tripse avatar tracywhodoesnot avatar โญ ๐Ÿพ avatar WtZ avatar David B. avatar  avatar  avatar  avatar Kevin avatar James Yeung avatar  avatar barry avatar Thomas DIOT avatar Curtis Ringwald avatar d0gkiller87 avatar Ryan Stephenson avatar Mitch Hines avatar  avatar Raul avatar  avatar Filippos Mastrogiannis avatar epichoxha avatar febiNJ avatar y.kankaya avatar  avatar  avatar Borja Merino avatar  avatar Chopicalqui avatar stroblite avatar litsnarf avatar Ceramicskate0 avatar  avatar Saad Azghour avatar Riccardo Ancarani avatar changheluori007 avatar bopin avatar t43M!ne avatar  avatar Bobby Cooke avatar Johnny Reina avatar  avatar Jules avatar Nick Aliferopoulos avatar  avatar cances avatar Chris Lin avatar  avatar  avatar parzival avatar NULL avatar Tyler Robinson avatar Mariusz Banach avatar ็ช็ชๅ…” avatar Martin avatar Sp4ce avatar Evangelos Mitakidis avatar Ryan Baxendale avatar  avatar Ronan Kervella avatar  avatar  avatar Joe avatar Abrar Fahim avatar Katze avatar  avatar  avatar  avatar  avatar TimWhite avatar crusher avatar 0x00 avatar  avatar z3r0yu avatar  avatar  avatar ak74 avatar Michael Eder avatar Boschko avatar beerandgin avatar Michael Miles avatar  avatar snovvcrash avatar Mez0 avatar Erik avatar

Watchers

 avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.