Added CobaltSplunk

This commit is contained in:
Mariusz B. / mgeeky 2021-03-15 02:33:37 +01:00
parent e8c3d8dae7
commit d981ff1552
4 changed files with 6 additions and 0 deletions

3
.gitmodules vendored
View File

@ -49,3 +49,6 @@
[submodule "windows/UnhookMe"] [submodule "windows/UnhookMe"]
path = windows/UnhookMe path = windows/UnhookMe
url = https://github.com/mgeeky/UnhookMe url = https://github.com/mgeeky/UnhookMe
[submodule "red-teaming/CobaltSplunk"]
path = red-teaming/CobaltSplunk
url = https://github.com/mgeeky/CobaltSplunk

@ -0,0 +1 @@
Subproject commit 69cfd3da3dfe6524930d489ffa483b2b1b36f754

View File

@ -52,6 +52,8 @@ cmstp.exe /ni /s cmstp.inf
- **`cobalt-arsenal`** - A set of my published Cobalt Strike 4.0+ compatible aggressor scripts. That includes couple of my handy utils I've used on various engagements. - **`cobalt-arsenal`** - A set of my published Cobalt Strike 4.0+ compatible aggressor scripts. That includes couple of my handy utils I've used on various engagements.
- **`CobaltSplunk`** - Originally devised by [Vincent Yiu](https://github.com/vysecurity/CobaltSplunk), heavily reworked by me: a Splunk application that ingests, indexes and exposes several search operators to work with Cobalt Strike logs from within of a Splunk interface. Supports Cobalt Strike 4.3+ log files syntax. Gives a lot of flexibility to work with Teamserver log files, search through them, generate insightful reports/dashboards/pivot tables and much more.
- [**`code-exec-templates`**](https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/red-teaming/code-exec-templates) - a small collection of template/backbone files for various code-execution techniques (VBScript/JScript embedded in HTA/SCT/XSL/VBS/JS) - [**`code-exec-templates`**](https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/red-teaming/code-exec-templates) - a small collection of template/backbone files for various code-execution techniques (VBScript/JScript embedded in HTA/SCT/XSL/VBS/JS)
- **`compressedPowershell.py`** - Creates a Powershell snippet containing GZIP-Compressed payload that will get decompressed and executed (IEX) - **`compressedPowershell.py`** - Creates a Powershell snippet containing GZIP-Compressed payload that will get decompressed and executed (IEX)

Binary file not shown.