{"id":556,"date":"2022-08-17T23:16:39","date_gmt":"2022-08-17T15:16:39","guid":{"rendered":"http:\/\/www.aqwu.net\/wp\/?p=556"},"modified":"2022-08-17T23:16:39","modified_gmt":"2022-08-17T15:16:39","slug":"cobalt-strike-4-7%ef%bc%9a%e5%8d%81%e5%91%a8%e5%b9%b4%e7%ba%aa%e5%bf%b5%e7%89%88","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=556","title":{"rendered":"Cobalt Strike 4.7\uff1a\u5341\u5468\u5e74\u7eaa\u5ff5\u7248"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">\u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www.cobaltstrike.com\/blog\/cobalt-strike-4-7-the-10th-anniversary-edition\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cobalt Strike 4.7 \u73b0\u5df2\u63a8\u51fa\u3002\u6b64\u7248\u672c\u652f\u6301 SOCKS5\u3001\u63d0\u4f9b\u7075\u6d3b\u7684 BOF \u5b58\u50a8\u5728\u5185\u5b58\u4e2d\u7684\u65b0\u9009\u9879\u3001Beacon \u7761\u7720\u65b9\u5f0f\u7684\u66f4\u65b0\u4ee5\u53ca\u6211\u4eec\u7528\u6237\u8981\u6c42\u7684\u8bb8\u591a\u5176\u4ed6\u66f4\u6539\u3002\u6211\u4eec\u8fd8\u5bf9\u7528\u6237\u754c\u9762\u8fdb\u884c\u4e86\u4e00\u4e9b\u66f4\u65b0\uff08\u5305\u62ec\u5bf9\u6025\u9700\u7684\u6697\u6a21\u5f0f\u7684\u652f\u6301\uff01\uff09\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3a\u7eaa\u5ff5Cobalt Strike \u6210\u7acb 10<sup>\u5468\u5e74<\/sup>\uff0c\u6211\u8981\u8877\u5fc3\u611f\u8c22\u6240\u6709\u7528\u6237\u591a\u5e74\u6765\u7684\u6301\u7eed\u652f\u6301\u2014\u2014\u4ece Raphael Mudge \u521b\u5efa\u7684\u7b2c\u4e00\u4e2a\u7248\u672c\uff0c\u5230\u88ab HelpSystems \u6536\u8d2d\uff0c\u76f4\u5230\u4eca\u5929\u8d85\u8d8a\u3002\u5f53\u6211\u7b2c\u4e00\u6b21\u89c1\u5230 Raphael \u65f6\uff0c\u4ed6\u7ed9\u6211\u7559\u4e0b\u4e86\u6df1\u523b\u7684\u5370\u8c61\uff0cCobalt Strike \u7684\u7528\u6237\u793e\u533a\u662f\u591a\u4e48\u72ec\u7279\u548c\u7279\u522b\uff0c\u6211\u6bcf\u5929\u90fd\u5728\u63d0\u9192\u6211\u2014\u2014\u4ece\u793e\u4ea4\u5a92\u4f53\u4e0a\u7684\u4e92\u52a8\uff0c\u5230\u63d0\u4ea4\u5230<a href=\"https:\/\/www.cobaltstrike.com\/blog\/introducing-cobalt-strike-community-kit\/\">\u793e\u533a\u5de5\u5177\u5305<\/a>\u548c\u6240\u6709\u4f1f\u5927\u7684\uff08\u4ee5\u53ca\u8001\u5b9e\u8bf4\uff0c\u6709\u65f6\u4e0d\u662f\u5f88\u597d\uff01\uff09\u6211\u4eec\u6536\u5230\u7684\u53cd\u9988\u3002\u6ca1\u6709\u60a8\u7684\u652f\u6301\u548c\u4e0d\u65ad\u7684\u53cd\u9988\uff0cCobalt Strike \u4e0d\u4f1a\u6709\u4eca\u5929\u7684\u6210\u5c31\uff0c\u6240\u4ee5\u8c22\u8c22\u60a8\u3002\u8fd9\u662f\u672a\u676510\u5e74\uff01<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8e\u9003\u907f\uff08Evasion\uff09\u7684\u4e00\u53e5\u8bdd<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u6df1\u5165\u4e86\u89e3 4.7 \u7248\u672c\u7684\u7ec6\u8282\u4e4b\u524d\uff0c\u6211\u60f3\u82b1\u4e00\u70b9\u65f6\u95f4\u8c08\u8c08\u8be5\u7248\u672c<em>\u4e2d\u6ca1\u6709<\/em>\u7684\u5185\u5bb9\u3002\u5728\u8fc7\u53bb\u7684\u51e0\u4e2a\u6708\u91cc\uff0c\u6211\u4eec\u6536\u5230\u4e86\u5f88\u591a\u53cd\u9988\uff0c\u8868\u660e Cobalt Strike \u6b63\u5728\u88ab\u79ef\u6781\u5730\u6307\u7eb9\u8bc6\u522b\uff0c\u8fd9\u4f7f\u5f97\u7ed5\u8fc7 AV \u548c EDR \u5de5\u5177\u53d8\u5f97\u56f0\u96be\u3002\u5bf9\u4e8e\u6ca1\u6709\u65f6\u95f4\u5f00\u53d1\u81ea\u5df1\u7684\u5de5\u5177\u7684\u56e2\u961f\u6765\u8bf4\uff0c\u8fd9\u8ba9\u4e8b\u60c5\u53d8\u5f97\u7279\u522b\u56f0\u96be\uff0c\u60a8\u53ef\u80fd\u4e00\u76f4\u671f\u671b 4.7 \u7248\u672c\u4e2d\u7684\u66f4\u6539\u4f1a\u63a8\u8fdf\u8fd9\u4e00\u70b9\u3002\u7136\u800c\uff0c\u6b63\u5982\u6211\u5728<a href=\"https:\/\/www.cobaltstrike.com\/blog\/cobalt-strike-roadmap-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u4e00\u7bc7\u5173\u4e8e\u6211\u4eec\u8def\u7ebf\u56fe\u7684\u535a\u5ba2\u6587\u7ae0\u4e2d\u63d0\u5230\u7684\u90a3\u6837<\/a>\u65e9\u5728 3 \u6708\uff0c\u6211\u4eec\u5c31\u4e0d\u4f1a\u5728\u6838\u5fc3 Cobalt Strike \u4ea7\u54c1\u4e2d\u6dfb\u52a0\u4efb\u4f55\u5f00\u7bb1\u5373\u7528\u7684\u89c4\u907f\u63aa\u65bd\uff08\u4e3a\u4e86\u907f\u514d\u91cd\u590d\u6211\u81ea\u5df1\uff0c\u8bf7\u9605\u8bfb\u535a\u6587\uff0c\u56e0\u4e3a\u5b83\u6df1\u5165\u4e86\u89e3\u4e86\u4e3a\u4ec0\u4e48\u4f1a\u8fd9\u6837\uff09 .&nbsp;\u8fd9\u5e76\u4e0d\u662f\u8bf4\u6211\u4eec\u6839\u672c\u6ca1\u6709\u505a\u4efb\u4f55\u4e8b\u60c5\u2014\u2014\u6211\u4eec\u5f53\u7136\u4f1a\u8ba4\u771f\u5bf9\u5f85\u8fd9\u4e00\u70b9\uff0c\u5f53\u7136\u6211\u4eec\u6b63\u5728\u96c6\u4e2d\u7cbe\u529b\u8fdb\u884c\u6539\u8fdb\u3002\u6211\u4eec\u7684\u4e3b\u8981\u4ea7\u54c1\u7248\u672c\u5c06\u7ee7\u7eed\u589e\u52a0\u7075\u6d3b\u6027\uff0c\u5bf9\u7528\u6237\u8981\u6c42\u7684\u4ea7\u54c1\u8fdb\u884c\u66f4\u6539\uff0c\u5e76\u4fdd\u6301\u7a33\u5b9a\u3002\u4e0e\u6b64\u540c\u65f6\uff0c\u6211\u4eec\u4e0d\u65ad\u58ee\u5927\u7684\u7814\u7a76\u56e2\u961f\u5c06\u4e13\u6ce8\u4e8e\u5728\u4e3b\u53d1\u5e03\u5468\u671f\u4e4b\u5916\u5411\u963f\u68ee\u7eb3\u5de5\u5177\u5305\u6dfb\u52a0\u65b0\u7684\u548c\u66f4\u65b0\u73b0\u6709\u7684\u89c4\u907f\u5de5\u5177\uff0c\u5728\u4e0d\u5f71\u54cd\u6216\u8ba9\u60a8\u7b49\u5f85\u4e3b\u8981\u4ea7\u54c1\u53d1\u5e03\u7684\u60c5\u51b5\u4e0b\u4fdd\u6301\u8fdb\u5c55\u3002\u4ece\u957f\u8fdc\u6765\u770b\uff0c\u8fd9\u5bf9\u6211\u4eec\u7684\u7528\u6237\u6765\u8bf4\u5e94\u8be5\u4f1a\u66f4\u597d\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HelpSystems \u7ee7\u7eed\u6295\u8d44\u4e8e\u5f00\u53d1\u56e2\u961f\u548c\u7814\u7a76\u56e2\u961f\u3002\u6211\u4eec\u6700\u8fd1\u5728 Cobalt Strike Arsenal Kit \u4e2d\u53d1\u5e03\u4e86\u4e00\u4e2a<a href=\"https:\/\/www.cobaltstrike.com\/blog\/arsenal-kit-update-thread-stack-spoofing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Thread Stack Spoofing \u5de5\u5177<\/a>\uff0c\u6211\u4eec\u8fd8\u6709\u8bb8\u591a\u5176\u4ed6\u5de5\u5177\u76ee\u524d\u6b63\u5728\u5f00\u53d1\u4e2d\uff0c\u6211\u4eec\u9884\u8ba1\u5c06\u5728\u63a5\u4e0b\u6765\u7684\u51e0\u5468\u5185\u53d1\u5e03\uff0c\u4ee5\u586b\u8865\u73b0\u5728\u548c\u6700\u7ec8 4.8 \u7248\u672c\u4e4b\u95f4\u7684\u7a7a\u767d\u5e74\u3002\u8fd9\u6837\u505a\u7684\u539f\u56e0\u662f\u4e3a\u4e86\u5411\u5927\u5bb6\u4fdd\u8bc1\uff0c\u6211\u4eec\u975e\u5e38\u6e05\u695a\u60a8\u6240\u9762\u4e34\u7684\u95ee\u9898\uff0c\u867d\u7136 4.7 \u7248\u672c\u672c\u8eab\u4e0d\u5305\u542b\u5927\u91cf\u5de5\u5177\u6765\u89e3\u51b3\u89c4\u907f\u95ee\u9898\uff0c\u4f46\u6211\u4eec\u5df2\u7ecf\u8ba4\u771f\u5bf9\u5f85\u8fd9\u4e00\u70b9\u5728\u540e\u53f0\u5904\u7406\u8fd9\u4e2a\u3002\u611f\u8c22\u5927\u5bb6\u7684\u8010\u5fc3\u7b49\u5f85\uff0c\u56e0\u4e3a\u6211\u4eec\u7684\u7814\u7a76\u56e2\u961f\u5df2\u7ecf\u7ad9\u7a33\u811a\u8ddf\uff0c\u7814\u7a76\u5de5\u4f5c\u4e5f\u5728\u52a0\u7d27\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u73b0\u5728\uff0c\u56de\u5230 4.7 \u7248\u672c\u7684\u7ec6\u8282\u3002\u6bd5\u7adf\uff0c\u8fd9\u5c31\u662f\u4f60\u6765\u8fd9\u91cc\u7684\u76ee\u7684\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SOCKS5 \u4ee3\u7406\u670d\u52a1\u5668\u652f\u6301<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6b64\u7248\u672c\u5b9e\u73b0\u4e86\u4e00\u4e2a\u6d41\u884c\u7684\u529f\u80fd\u8bf7\u6c42\u2014\u2014\u5bf9 SOCKS5 \u7684\u652f\u6301\u3002\u4e0e\u5176\u5b8c\u5168\u66ff\u6362 SOCKS4a\uff0c\u4e0d\u5982\u5728\u542f\u52a8 SOCKS \u65f6\u9009\u62e9\u662f\u4f7f\u7528 SOCKS4a \u8fd8\u662f SOCKS5\u3002\u8fdb\u884c\u4e86\u8bb8\u591a\u66f4\u6539\uff0c\u5305\u62ec\u66f4\u65b0\u201c\u542f\u52a8 SOCKS\u201d\u5bf9\u8bdd\u6846\u4ee5\u4f7f\u60a8\u80fd\u591f\u5728 SOCKS4a \u548c SOCKS5 \u4e4b\u95f4\u8fdb\u884c\u9009\u62e9\uff08\u4ee5\u53ca\u5982\u679c\u9009\u62e9\u4e86 SOCKS5\uff0c\u5219\u8f93\u5165\u6240\u9700\u7684\u53c2\u6570\uff09\uff0c\u66f4\u65b0\u4ee3\u7406\u67a2\u8f74\u8868\u4ee5\u663e\u793a\u662f\u5426\u6b63\u5728\u4f7f\u7528 SOCKS4a \u6216 SOCKS5\uff0c\u66f4\u65b0\u4e86 Beacon \u63a7\u5236\u53f0\u4e2d\u542f\u52a8\u548c\u505c\u6b62 SOCKS \u7684\u547d\u4ee4\uff0c\u4ee5\u53ca\u66f4\u65b0\u4e86<strong>bsocks Aggressor<\/strong>\u811a\u672c\u547d\u4ee4\u3002\u6709\u5173\u65b0\u547d\u4ee4\u884c\u9009\u9879\u7684\u8be6\u7ec6\u4fe1\u606f\uff0c\u8bf7\u5728 Beacon \u63a7\u5236\u53f0\u4e2d\u8fd0\u884c<strong>help socks \u3002<\/strong>\u6709\u5173\u66f4\u6539\u7684\u4e00\u822c\u8be6\u7ec6\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605<a href=\"https:\/\/hstechdocs.helpsystems.com\/manuals\/cobaltstrike\/current\/userguide\/content\/topics\/welcome_main.htm?__hstc=173638140.1bf2de6f6b2e1d2acf49d451702827bc.1660704253857.1660704253857.1660748841078.2&amp;__hssc=173638140.1.1660748841078&amp;__hsfp=1376655195\" target=\"_blank\" rel=\"noreferrer noopener\">\u6587\u6863<\/a>\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0c\u8fd9\u4e9b\u66f4\u6539\u76ee\u524d\u4ec5\u6dfb\u52a0\u4e86\u5bf9 DNS \u89e3\u6790\u548c UDP \u7684\u652f\u6301\u3002\u5728\u6b64\u7248\u672c\u4e2d\uff0c\u6211\u4eec<em>\u6ca1\u6709<\/em>\u6dfb\u52a0\u5bf9 IPv6 \u6216 GS\u200b\u200bSAPI \u8eab\u4efd\u9a8c\u8bc1\u7684\u652f\u6301\uff0c\u56e0\u4e3a\u6211\u4eec\u4ece\u60a8\u90a3\u91cc\u5f97\u5230\u7684\u53cd\u9988\u662f\u8fd9\u4e9b\u529f\u80fd\u5e76\u4e0d\u91cd\u8981\u3002\u5f53\u7136\uff0c\u6211\u4eec\u5c06\u7ee7\u7eed\u76d1\u63a7\u53cd\u9988\uff0c\u5e76\u5728\u60a8\u6307\u51fa\u6dfb\u52a0\u8fd9\u4e9b\u529f\u80fd\u5f88\u91cd\u8981\u65f6\u6dfb\u52a0\u5bf9\u8fd9\u4e9b\u529f\u80fd\u7684\u652f\u6301\u3002\u6211\u4eec\u8fd8\u6253\u7b97\u5728\u672a\u6765\u7684\u7248\u672c\u4e2d\u8fdb\u884c\u5176\u4ed6\u66f4\u6539\uff0c\u5305\u62ec\u5c06 SOCKS5 \u4e0e Beacon \u5206\u79bb\uff0c\u8fd9\u5c06\u63d0\u9ad8\u901f\u5ea6\u548c\u53ef\u9760\u6027\u3002\u4e0d\u8fc7\uff0c\u8fd9\u662f\u4e00\u4e2a\u66f4\u5927\u7684\u53d8\u5316\uff0c\u6211\u4eec\u5728\u6b64\u7248\u672c\u4e2d\u7684\u9996\u8981\u4efb\u52a1\u662f\u6dfb\u52a0\u6b64\u521d\u59cb\u652f\u6301\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/socks-1.png\" alt=\"\" class=\"wp-image-11122\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u589e\u52a0 BOF \u5982\u4f55\u5728\u5185\u5b58\u4e2d\u5b58\u5728\u7684\u7075\u6d3b\u6027<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Beacon \u5bf9\u8c61\u6587\u4ef6\u662f Cobalt Strike \u7684\u4e00\u4e2a\u5173\u952e\u7279\u6027\u3002\u6211\u4eec\u589e\u52a0\u4e86\u5173\u4e8e Beacon \u5bf9\u8c61\u6587\u4ef6\u5982\u4f55\u5728\u5185\u5b58\u4e2d\u5b58\u5728\u7684\u66f4\u591a\u53ef\u5851\u6027\uff0c\u8fd9\u5e94\u8be5\u4f7f\u5b83\u4eec\u66f4\u96be\u88ab\u6307\u7eb9\u8bc6\u522b\u3002\u4e3a\u6b64\uff0c\u6dfb\u52a0\u4e86\u4e24\u4e2a\u65b0\u7684 Malleable C2 \u914d\u7f6e\u6587\u4ef6\u8bbe\u7f6e\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><code>bof_allocator<\/code><\/em>\u63a7\u5236\u5982\u4f55\u4e3a BOF \u5206\u914d\u5185\u5b58\u3002\u652f\u6301\u7684\u8bbe\u7f6e\u662f<strong>VirtualAlloc<\/strong>\u3001<strong>MapViewOfFile<\/strong>\u548c<strong>HeapAlloc<\/strong>\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><code>bof_reuse_memory<\/code><\/em>\u786e\u5b9a\u662f\u5426\u91ca\u653e\u5185\u5b58\u3002\u5982\u679c\u6b64\u8bbe\u7f6e\u4e3a\u201ctrue\u201d\uff0c\u5219\u5185\u5b58\u88ab\u6e05\u9664\uff0c\u7136\u540e\u91cd\u65b0\u7528\u4e8e\u4e0b\u4e00\u6b21 BOF \u6267\u884c\uff1b\u5982\u679c\u6b64\u8bbe\u7f6e\u4e3a\u201cfalse\u201d\uff0c\u5219\u6839\u636e bof_allocator \u8bbe\u7f6e\u91ca\u653e\u5185\u5b58\u5e76\u4f7f\u7528\u9002\u5f53\u7684\u5185\u5b58\u91ca\u653e\u529f\u80fd\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5185\u5b58\u6743\u9650\uff08RWX\/RX \u6216 RW\/RX\uff09\u6839\u636e\u4e0a\u8ff0\u65b0\u7684 Malleable C2 \u914d\u7f6e\u6587\u4ef6\u8bbe\u7f6e\u4e2d\u8bbe\u7f6e\u7684\u503c\u8fdb\u884c\u8bbe\u7f6e\u3002HeapAlloc \u662f\u4e2a\u4f8b\u5916\uff0c\u5b83\u59cb\u7ec8\u662f RWX\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u56de\u987e VirtualAlloc RWX\/RX \u5185\u5b58\u7684 BOF \u4f7f\u7528\u60c5\u51b5<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u589e\u52a0 BOF \u5982\u4f55\u5728\u5185\u5b58\u4e2d\u5b58\u5728\u7684\u7075\u6d3b\u6027\u4e3a\u6211\u4eec\u63d0\u4f9b\u4e86\u89e3\u51b3\u6211\u4eec\u79ef\u538b\u7684\u53e6\u4e00\u4e2a\u9879\u76ee\u7684\u65b9\u6cd5\u3002\u6211\u4eec\u6dfb\u52a0\u4e86\u5bf9 BOF \u7684\u5176\u4ed6\u91cd\u5b9a\u4f4d\u7c7b\u578b\u7684\u652f\u6301\uff0c\u7279\u522b\u662f .xdata\u3001.pdata \u548c .bss \u90e8\u5206\u3002\u8fd9\u4e00\u53d8\u5316\u9996\u5148\u610f\u5473\u7740\u89e3\u51b3\u4e86\u4e00\u4e2a\u95ee\u9898\uff0c\u5373 BOF \u6709\u65f6\u65e0\u6cd5\u8fd0\u884c\uff0c\u56e0\u4e3a\u5730\u5740\u504f\u79fb\u91cf\u5927\u4e8e 4GB\u3002\u5176\u6b21\uff0c\u53ef\u7528\u52a8\u6001\u51fd\u6570\u7684\u6570\u91cf\u4ece 32 \u4e2a\u589e\u52a0\u5230 64 \u4e2a\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Sleep\u66f4\u65b0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u7761\u7720\u9762\u7f69\u5957\u4ef6\u548c\u4e00\u822c\u7761\u7720\u65b9\u9762\u5df2\u8fdb\u884c\u4e86\u66f4\u6539\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3b\u8981\u53d8\u5316\u662f\u60a8\u73b0\u5728\u53ef\u4ee5\u8986\u76d6 Beacon \u8fdb\u5165\u7761\u7720\u72b6\u6001\u65f6\u8c03\u7528\u7684\u65b9\u6cd5\u3002\u4ece 4.4 \u5230 4.6\uff0cBeacon \u5c06\u8c03\u7528\u4fee\u8865\u5230 .text \u90e8\u5206\u7684\u7761\u7720\u63a9\u7801\u51fd\u6570\u3002\u8fd9\u6709\u4e00\u4e9b\u7f3a\u70b9\uff0c\u56e0\u4e3a\u60a8\u53d7\u9650\u4e8e\u5982\u4f55\u5c06\u4ee3\u7801\u5199\u5165\u7528\u4e8e\u7f16\u5199 BOF \u7684 sleep_mask.c \u6587\u4ef6\u4e2d\uff0c\u5e76\u4e14\u8fd8\u6709\u4e00\u4e2a\u4e0e\u5927\u5c0f\u9650\u5236\u76f8\u5173\u7684\u95ee\u9898\u3002\u5728\u6b64\u7248\u672c\u4e2d\uff0cBeacon \u5df2\u7ecf\u8fc7\u91cd\u65b0\u8bbe\u8ba1\uff0c\u4ee5\u6dfb\u52a0\u5bf9\u60a8\u5728 BOF \u4e2d\u53ef\u4ee5\u5728\u7761\u7720\u4e2d\u6267\u884c\u7684\u6240\u6709\u64cd\u4f5c\u7684\u652f\u6301\u3002\u60a8\u73b0\u5728\u4e0d\u4ec5\u53ef\u4ee5\u4f7f\u7528\u81ea\u5df1\u7684 sleep \u51fd\u6570\uff0c\u8fd8\u53ef\u4ee5\u8c03\u7528\u52a8\u6001\u51fd\u6570 (LIBRARY$function) \u548c Beacon API \u51fd\u6570\uff08\u5f53 Beacon \u4ee3\u7801\u672a\u88ab\u5c4f\u853d\u65f6\uff09\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6b64\u66f4\u6539\u8fd8\u6709\u4e24\u4e2a\u5176\u4ed6\u597d\u5904\u503c\u5f97\u5f3a\u8c03\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u53ef\u6267\u884c\u4ee3\u7801\u73b0\u5728\u4e0d\u518d\u4f4d\u4e8e Beacon \u7684 .text \u90e8\u5206\uff0c\u800c\u662f\u79fb\u81f3\u4e0d\u540c\u7684\u5185\u5b58\u533a\u57df\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7761\u7720\u63a9\u7801 BOF \u5927\u5c0f\u9650\u5236\u5df2\u4ece 769 \u5b57\u8282\u589e\u52a0\u5230 8192 \u5b57\u8282\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0e\u6b64\u76f8\u5173\u7684\u662f\uff0c\u867d\u7136\u963f\u68ee\u7eb3\u5957\u4ef6\u4ecd\u652f\u6301\u65e7\u7248\u672c\u7684\u7761\u7720\u9762\u7f69\uff0c\u4f46\u6b64\u7248\u672c\u589e\u52a0\u4e86\u5bf9\u5c06\u7761\u7720\u9762\u7f69\u5b9e\u73b0\u4e3a\u771f\u6b63\u7684 BOF \u7684\u652f\u6301\u3002\u60a8\u9700\u8981\u63d0\u53d6\u66f4\u65b0\u540e\u7684\u963f\u68ee\u7eb3\u5957\u4ef6\u624d\u80fd\u4f7f\u7528\u6b64\u529f\u80fd\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7a83\u53d6\u4ee4\u724c\uff08Token\uff09\u66f4\u65b0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">steal_token\u51fd\u6570\u5df2\u66f4\u65b0\uff0c\u4f7f\u5176\u80fd\u591f\u4ece\u4ee5\u524d\u65e0\u6cd5\u8bbf\u95ee\u7684\u8fdb\u7a0b\u4e2d\u7a83\u53d6\u4ee4\u724c<em>\u3002<\/em>\u4e00\u4f4d\u7528\u6237\u62a5\u544a\u8bf4\uff0c\u5f53 Beacon \u4f7f\u7528 OpenProcessToken \u8bf7\u6c42<strong>TOKEN_ALL_ACCESS<\/strong>\u65f6\uff0c\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\u8fd9\u4f1a\u8fd4\u56de\u62d2\u7edd\u8bbf\u95ee\u9519\u8bef\u3002\u5f53 Beacon \u8c03\u7528 OpenProcessToken \u65f6\uff0c\u624b\u52a8\u8c03\u6574\u6743\u9650\u8db3\u4ee5\u8ba9\u4ed6\u4eec\u8ba9<em>\u7a83\u53d6\u4ee4\u724c<\/em>\u6210\u529f\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u91c7\u7eb3\u4e86\u6b64\u53cd\u9988\uff0c\u60a8\u73b0\u5728\u53ef\u4ee5\u5728\u8c03\u7528<em>steal_token<\/em>\u65f6\u81ea\u5b9a\u4e49\u8bbf\u95ee\u63a9\u7801\u3002\u4e3a\u4e86\u4fc3\u8fdb\u8fd9\u4e00\u70b9\uff0c\u5df2\u7ecf\u8fdb\u884c\u4e86\u8bb8\u591a\u66f4\u6539\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u4e2a<strong>steal_token_access_mask<\/strong>\u9009\u9879\u5df2\u6dfb\u52a0\u5230Malleable C2 \u914d\u7f6e\u6587\u4ef6\u4e2d\u3002\u8fd9\u662f\u53ef\u9009\u7684\uff0c\u5141\u8bb8\u60a8\u8bbe\u7f6e\u7528\u4e8e<em>Steal_token<\/em>\u548c<em>bsteal_token<\/em>\u7684\u9ed8\u8ba4\u8bbf\u95ee\u63a9\u7801\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6dfb\u52a0\u4e86\u652f\u6301\u4ee5\u5141\u8bb8\u60a8\u5728\u4ece\u547d\u4ee4\u884c\u8c03\u7528<em>steal_token<\/em>\u548c<em>bsteal_token<\/em>\u65f6\u8bbe\u7f6e\u8bbf\u95ee\u63a9\u7801\uff08\u5e76\u8986\u76d6\u9ed8\u8ba4\u503c\uff09 \u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Steal Token \u5bf9\u8bdd\u6846\u5df2\u66f4\u65b0\uff0c\u5141\u8bb8\u60a8\u8bbe\u7f6e\u8bbf\u95ee\u63a9\u7801\uff08\u5e76\u8986\u76d6\u9ed8\u8ba4\u503c\uff09\u3002\u8fd9\u9002\u7528\u4e8e\u5728\u6253\u5f00\u5bf9\u8bdd\u6846\u4e4b\u524d\u540c\u65f6\u9009\u62e9\u4e86\u5355\u4e2a\u8fdb\u7a0b\u548c\u591a\u4e2a\u8fdb\u7a0b\u7684\u60c5\u51b5\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bf7\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u63d0\u4f9b\u8bbf\u95ee\u63a9\u7801\u7684\u9ed8\u8ba4\u503c\uff08\u901a\u8fc7\u65b0\u7684 Malleable C2 \u914d\u7f6e\u6587\u4ef6\u9009\u9879\u3001\u5bf9\u8bdd\u6846\u9009\u9879\u6216\u547d\u4ee4\u884c\u9009\u9879\uff09\uff0csteal_token \u5c06\u9ed8\u8ba4\u4e3a TOKEN_ALL_ACCESS \u7684\u5f53\u524d\u8bbf\u95ee<strong>\u63a9\u7801<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/steal_token1-1024x350.png\" alt=\"\" class=\"wp-image-11126\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u6a21\u5757\u8e29\u8e0f\uff08Module Stomping\u00a0\uff09\u66f4\u65b0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6839\u636e\u7528\u6237\u53cd\u9988\uff0c\u5bf9\u6a21\u5757\u8e29\u8e0f\u8fdb\u884c\u4e86\u5c0f\u5e45\u6539\u52a8\u3002\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\uff0c\u5c3d\u7ba1\u6a21\u5757\u5df2\u52a0\u8f7d\uff0c\u4f46\u5b9e\u9645\u8e29\u8e0f\u5931\u8d25\uff0c\u56e0\u4e3a Beacon \u4ecd\u4fdd\u7559\u5728\u865a\u62df\u5185\u5b58\u4e2d\u3002\u8fd9\u662f\u56e0\u4e3a\u9664\u975e\u5bfc\u51fa\u51fd\u6570\u7684\u5e8f\u6570\u503c\u4ecb\u4e8e 1 \u548c 15 \u4e4b\u95f4\uff0c\u5426\u5219 Beacon \u5c06\u9ed8\u8ba4\u4f7f\u7528 VirtualAlloc\u3002\u73b0\u5728\uff0c\u901a\u8fc7\u5728\u8bbe\u7f6e\u4e2d\u6dfb\u52a0\u53ef\u9009\u8bed\u6cd5\u4ee5\u5728\u641c\u7d22\u5bfc\u51fa\u51fd\u6570\u65f6\u6307\u5b9a\u8d77\u59cb\u5e8f\u6570\uff0c\u6b64\u9650\u5236\u5df2\u5f97\u5230\u89e3\u51b3\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u526a\u8d34\u677f\u7a83\u53d6\u8005\uff08Clipboard Stealer\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u60a8\u73b0\u5728\u53ef\u4ee5\u901a\u8fc7\u547d\u4ee4 (&nbsp;<strong>clipboard<\/strong>&nbsp;) \u6216 Aggressor \u811a\u672c\u547d\u4ee4 (&nbsp;<strong>bclipboard ) \u7a83\u53d6\u76ee\u6807\u7cfb\u7edf\u4e0a Windows \u526a\u8d34\u677f\u7684\u5185\u5bb9<\/strong>)\uff0c\u4f46\u9700\u8981\u6ce8\u610f\u7684\u662f\uff1a\u6b64\u529f\u80fd\u4ec5\u5728\u526a\u8d34\u677f\u5305\u542b\u6587\u672c\uff08\u4f8b\u5982\u51ed\u8bc1\u6750\u6599\uff09\u65f6\u624d\u6709\u7528\u3002\u8fd9\u662f\u4e00\u4e2a\u5feb\u901f\u66f4\u6539\uff0c\u9884\u671f\u7528\u4f8b\u9002\u7528\u4e8e\u4f7f\u7528\u5bc6\u7801\u7ba1\u7406\u5668\uff08\u6216\u7c7b\u4f3c\u5de5\u5177\uff09\u89c2\u5bdf\u5230\u76ee\u6807\u4ee5\u83b7\u53d6\u5bc6\u7801\u7684\u60c5\u51b5\uff1b\u7136\u540e\uff0c\u60a8\u5c31\u53ef\u4ee5\u4ece\u526a\u8d34\u677f\u590d\u5236\u8be5\u5bc6\u7801\uff08\u6216\u5176\u4ed6\u76f8\u5173\u6750\u6599\uff09\u4ee5\u4f9b\u4f7f\u7528\u3002\u5982\u679c\u526a\u8d34\u677f\u4e0a\u6709\u6587\u672c\uff0c\u5219\u8fd4\u56de\u5e76\u663e\u793a\uff1b\u5982\u679c\u6ca1\u6709\uff0c\u5c06\u663e\u793a\u4e00\u4e2a\u9519\u8bef\uff0c\u901a\u77e5\u60a8\u526a\u8d34\u677f\u5185\u5bb9\u4e0d\u662f\u57fa\u4e8e\u6587\u672c\u7684\u3002\u4f8b\u5916\u60c5\u51b5\u662f\uff0c\u5982\u679c\u526a\u8d34\u677f\u5185\u5bb9\u8d85\u8fc7 204800 \u5b57\u8282\uff0c\u5219\u4f1a\u8fd4\u56de\u9519\u8bef\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136\u8fd9\u662f\u4e00\u4e2a\u8303\u56f4\u6709\u9650\u7684\u5feb\u901f\u66f4\u6539\uff0c\u4f46\u6211\u4eec\u53ef\u80fd\u4f1a\u5728\u672a\u6765\u7684\u7248\u672c\u4e2d\u589e\u5f3a\u6b64\u529f\u80fd\u3002\u6211\u4eec\u53ef\u4ee5\u91c7\u7528\u8bb8\u591a\u6709\u8da3\u7684\u65b9\u5411\uff0c\u6211\u4eec\u5f88\u60f3\u542c\u542c\u60a8\u7684\u53cd\u9988\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7528\u6237\u754c\u9762\/\u9ed8\u8ba4\u653b\u51fb\u8005\u811a\u672c\u66f4\u65b0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6b64\u7248\u672c\u5bf9\u5ba2\u6237\u7aef UI \u7684\u5916\u89c2\u548c\u611f\u89c9\u8fdb\u884c\u4e86\u66f4\u65b0\uff08\u5c3d\u7ba1\u4e0d\u662f\u6211\u4eec\u4ecd\u5728\u4e3a\u672a\u6765\u7248\u672c\u8003\u8651\u7684\u5168\u9762\u5927\u4fee\uff09\uff0c\u540c\u65f6\u5bf9\u9ed8\u8ba4\u653b\u51fb\u8005\u811a\u672c\u8fdb\u884c\u4e86\u4e00\u4e9b\u66f4\u6539\uff0c\u4ece\u800c\u5f15\u5165\u4e86\u4e00\u4e9b\u53ef\u7528\u6027\u6539\u8fdb\u3002\u60a8\u53ef\u80fd\u4f1a\u8ba4\u51fa\u4e00\u4e9b\u9ed8\u8ba4\u7684 Aggressor \u811a\u672c\u66f4\u6539\uff0c\u56e0\u4e3a\u5176\u4e2d\u4e00\u4e9b\u66f4\u6539\u662f\u53d7\u5230<a href=\"https:\/\/github.com\/mgeeky\/cobalt-arsenal\" target=\"_blank\" rel=\"noreferrer noopener\">mgeeky \u7684\u201ccobalt-arsenal\u201d Aggressor \u811a\u672c\u7684<\/a>\u542f\u53d1\uff08\u5076\u7136\u53ef\u4ee5\u5728<a href=\"https:\/\/cobalt-strike.github.io\/community_kit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cobalt Strike \u793e\u533a\u5de5\u5177\u5305<\/a>\u4e2d\u627e\u5230\uff09\u3002\u867d\u7136\u6211\u4eec\u4e5f\u6dfb\u52a0\u4e86\u6211\u4eec\u81ea\u5df1\u7684\u66f4\u6539\u5e76\u4ee5\u6211\u4eec\u81ea\u5df1\u7684\u65b9\u5f0f\u5b9e\u73b0\u4e86\u4e00\u4e9b\u4e1c\u897f\uff0c\u4f46\u6211\u4eec\u975e\u5e38\u611f\u8c22 mgeeky \u5141\u8bb8\u5c06\u5176\u4e2d\u4e00\u4e9b\u529f\u80fd\u5e26\u5165 Cobalt Strike \u672c\u8eab\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u5728\u8fd9\u65b9\u9762\u505a\u4e86\u4e00\u4e9b\u6539\u53d8\u3002\u4ee5\u4e0b\u662f\u4e00\u4e9b\u4eae\u70b9\uff1a<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u9ed1\u6697\u6a21\u5f0f<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u5f15\u4eba\u6ce8\u76ee\u7684\u53d8\u5316\uff08\u4e5f\u662f\u6700\u9700\u8981\u7684\u53d8\u5316\u4e4b\u4e00\uff09\u662f\u589e\u52a0\u4e86\u6697\u6a21\u5f0f\u3002\u8fd9\u53ef\u4ee5\u901a\u8fc7\u65b0\u7684\u83dc\u5355\u9009\u9879\u8fdb\u884c\u5207\u6362\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/dark-mode-1024x759.png\" alt=\"\" class=\"wp-image-11129\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong><strong>Sleep Time<\/strong><\/strong> <strong>\u8ddf\u8e2a<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u7761\u7720\u65f6\u95f4\u8ddf\u8e2a\u901a\u8fc7\u8bb0\u5f55\u6bcf\u4e2a Beacon \u7684\u7761\u7720\u65f6\u95f4\u5e76\u5c06\u5176\u663e\u793a\u5728 Beacon \u8868\u89c6\u56fe\u7684\u65b0\u5217\u4e2d\u6765\u5de5\u4f5c\u3002\u6b64\u4fe1\u606f\u5728\u56e2\u961f\u670d\u52a1\u5668\u91cd\u65b0\u542f\u52a8\u4e4b\u95f4\u4fdd\u7559\uff0c\u56e0\u6b64\u5b83\u5e94\u8be5\u59cb\u7ec8\u53ef\u7528\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u4fe1\u6807\u5065\u5eb7\uff08<strong>Beacon Health<\/strong><\/strong>\uff09<strong>\u8ddf\u8e2a<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0e\u7761\u7720\u65f6\u95f4\u8ddf\u8e2a\u76f8\u5173\u7684\u662f\u65b0\u7684 Beacon Health \u8ddf\u8e2a\u529f\u80fd\u3002\u6b64\u529f\u80fd\u4f7f\u7528\u7761\u7720\u65f6\u95f4\u5e76\u5c06\u5176\u4e0e\u4e0a\u6b21\u7b7e\u5165\u65f6\u95f4\u4ea4\u53c9\u5f15\u7528\uff0c\u4ee5\u786e\u5b9a\u4fe1\u6807\u662f\u5904\u4e8e\u6d3b\u52a8\u72b6\u6001\u3001\u65ad\u5f00\u8fde\u63a5\u8fd8\u662f\u6b7b\u4ea1\u3002\u6b64\u4fe1\u606f\u663e\u793a\u5728 Beacon \u8868\u89c6\u56fe\u4e2d\u5e76\u53cd\u6620\u5728 Beacon \u7684\u56fe\u6807\u4e2d\u3002\u53ef\u4ee5\u901a\u8fc7\u9996\u9009\u9879\u5bf9\u8bdd\u6846\u4e0a\u7684\u65b0\u9009\u9879\u542f\u7528\u6216\u7981\u7528\u6b64\u529f\u80fd\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/sleep-tracking-beacon-health-1-1024x291.png\" alt=\"\" class=\"wp-image-11131\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u56fe\u6807\uff08<strong>Icon<\/strong><\/strong>\uff09<strong>\u66f4\u65b0<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bf4\u5230\u56fe\u6807\uff0c\u6211\u4eec\u66f4\u65b0\u4e86\u900f\u89c6\u56fe\u548c Beacon \u8868\u89c6\u56fe\u4e2d\u4f7f\u7528\u7684\u56fe\u6807\uff0c\u4ee5\u8868\u793a Beacon \u72b6\u6001\u548c\u64cd\u4f5c\u7cfb\u7edf\u7c7b\u578b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/pivot-chart-icons-1024x930.png\" alt=\"\" class=\"wp-image-11132\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u5de5\u5177\u680f\u548c\u83dc\u5355\u66f4\u65b0<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u8fd8\u66f4\u65b0\u4e86\u5ba2\u6237\u7aef\u5de5\u5177\u680f\u4e0a\u7684\u56fe\u6807\uff0c\u5e76\u5220\u9664\u4e86\u4e00\u4e9b\u4e0d\u592a\u53d7\u6b22\u8fce\u7684\u529f\u80fd\u7684\u5de5\u5177\u680f\u6309\u94ae\u3002\u4e0e\u6b64\u66f4\u6539\u76f8\u5173\u7684\u662f\uff0c\u4e3b\u83dc\u5355\u5df2\u91cd\u65b0\u7ec4\u7ec7\uff0c\u5c06\u83dc\u5355\u6241\u5e73\u5316\u5e76\u5c06\u4e00\u4e9b\u9009\u9879\u79fb\u52a8\u5230\u66f4\u6709\u7528\u548c\u66f4\u76f4\u89c2\u7684\u4f4d\u7f6e\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u6279\u91cf\u6709\u6548\u8d1f\u8f7d\uff08<strong>Bulk Payload<\/strong><\/strong>\uff09<strong>\u751f\u6210<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0e\u83dc\u5355\u91cd\u7ec4\u76f8\u5173\uff0c\u6211\u4eec\u6dfb\u52a0\u4e86\u4e00\u4e2a\u65b0\u83dc\u5355\u9879\uff0c\u5141\u8bb8\u60a8\u4e00\u6b21\u4e3a\u6240\u6709\u53ef\u7528\u7684\u6709\u6548\u8d1f\u8f7d\u53d8\u4f53\u751f\u6210 x86 \u548c x64 \u65e0\u9636\u6bb5\u6709\u6548\u8d1f\u8f7d\u3002\u8fd8\u6dfb\u52a0\u4e86\u4e00\u4e2a\u65b0\u7684\u7761\u7720\u51fd\u6570<strong>all_payloads<\/strong>\u4ee5\u5141\u8bb8\u60a8\u4ece\u547d\u4ee4\u884c\u6267\u884c\u6b64\u64cd\u4f5c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/payloads-menu-1024x487.png\" alt=\"\" class=\"wp-image-11133\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u5177\u6709\u9000\u51fa\u9009\u9879\u7684\u65e0\u9636\u6bb5\u6709\u6548\u8d1f\u8f7d\uff08<strong>Stageless Payload<\/strong><\/strong>\uff09<strong>\u751f\u6210\u5668<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u6dfb\u52a0\u4e86\u4e00\u4e2a\u65e0\u9636\u6bb5\u6709\u6548\u8d1f\u8f7d\u751f\u6210\u5668\u5bf9\u8bdd\u6846\uff0c\u5141\u8bb8\u60a8\u5c06\u201c\u7ebf\u7a0b\u201d\u6216\u201c\u8fdb\u7a0b\u201d\u8bbe\u7f6e\u4e3a\u9000\u51fa\u9009\u9879\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/stageless-payload-generator.png\" alt=\"\" class=\"wp-image-11134\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Windows \u9519\u8bef\u4ee3\u7801\u89e3\u51b3\u65b9\u6848<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Windows \u9519\u8bef\u4ee3\u7801\u73b0\u5728\u53ef\u4ee5\u81ea\u52a8\u89e3\u6790\u548c\u89e3\u51b3\uff0c\u56e0\u6b64\u60a8\u4e0d\u518d\u9700\u8981\u8bb0\u4f4f\u6bcf\u4e2a Windows \u9519\u8bef\u4ee3\u7801\u6216\u5728 Beacon \u521a\u521a\u8fd4\u56de\u9519\u8bef\u4ee3\u7801\u65f6\u53bb\u67e5\u627e\u5b83\u3002\u76f8\u5173\u7684\u9519\u8bef\u6d88\u606f\u73b0\u5728\u663e\u793a\u5728\u9519\u8bef\u4ee3\u7801\u65c1\u8fb9\u3002\u6211\u4eec\u8fd8\u6dfb\u52a0\u4e86\u4e00\u4e2a\u65b0\u7684 Beacon \u63a7\u5236\u53f0\u547d\u4ee4 (&nbsp;<strong>windows_error_code<\/strong>&nbsp;) \u548c\u4e00\u4e2a Aggressor \u811a\u672c\u51fd\u6570 (&nbsp;<strong>windows_error_code<\/strong>&nbsp;)\uff0c\u53ef\u7528\u4e8e\u6309\u9700\u5c06\u9519\u8bef\u4ee3\u7801\u8f6c\u6362\u4e3a\u6d88\u606f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/error-code-resolution-1024x373.png\" alt=\"\" class=\"wp-image-11136\"\/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>\u8fdb\u7a0b\u5217\u8868\u663e\u793a\u66f4\u65b0<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ps<\/strong>\u547d\u4ee4\u7684\u8f93\u51fa\u5df2\u5f97\u5230\u589e\u5f3a\uff0c\u4ee5\u89e3\u51b3\u7236\/\u5b50\u5173\u7cfb\u5e76\u5c06\u8fdb\u7a0b\u5217\u8868\u663e\u793a\u4e3a\u6811\u89c6\u56fe\uff0c\u800c\u4e0d\u662f\u65e7\u7684\u5e73\u9762\u7248\u672c\u3002Beacon \u8fdb\u7a0b\u663e\u793a\u4e3a\u9ec4\u8272\u3002\u6211\u4eec\u8fd8\u8ba1\u5212\u5728\u672a\u6765\u7684\u7248\u672c\u4e2d\u901a\u8fc7\u66f4\u591a\u989c\u8272\u7f16\u7801\u6765\u589e\u5f3a\u8fd9\u4e00\u70b9\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.cobaltstrike.com\/wp-content\/uploads\/2022\/08\/ps-treeview-758x1024.png\" alt=\"\" class=\"wp-image-11137\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd8\u5b9e\u73b0\u4e86\u8bb8\u591a\u5176\u4ed6 UI \u66f4\u6539\uff0c\u5305\u62ec\u5728\u4fe1\u6807\u548c\u4e8b\u4ef6\u72b6\u6001\u680f\u4e2d\u663e\u793a\u66f4\u591a\u4fe1\u606f\u3001\u663e\u793a\u65f6\u95f4\u6233\u3001\u66f4\u5bb9\u6613\u4e0e\u4fe1\u6807\u4ea4\u4e92\u3001\u65b0\u7684\u201c\u5bfc\u5165\u51ed\u636e\u201d\u9009\u9879\u7b49\u7b49\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8981\u67e5\u770b Cobalt Strike 4.7 \u65b0\u529f\u80fd\u7684\u5b8c\u6574\u5217\u8868\uff0c\u8bf7\u67e5\u770b<a href=\"https:\/\/download.cobaltstrike.com\/releasenotes.txt\" target=\"_blank\" rel=\"noreferrer noopener\">\u53d1\u884c\u8bf4\u660e<\/a>\u3002\u83b7\u5f97\u8bb8\u53ef\u7684\u7528\u6237\u53ef\u4ee5&nbsp;<a href=\"https:\/\/www.cobaltstrike.com\/help-update-cobalt-strike\" target=\"_blank\" rel=\"noreferrer noopener\">\u8fd0\u884c\u66f4\u65b0\u7a0b\u5e8f\u4ee5\u83b7\u53d6\u6700\u65b0\u7248\u672c\uff0c\u6216\u4ece<\/a><a href=\"https:\/\/download.cobaltstrike.com\/download\" target=\"_blank\" rel=\"noreferrer noopener\">\u7f51\u7ad9<\/a>&nbsp;\u4ece\u5934\u4e0b\u8f7d 4.7 \u7248\u672c\u3002\u5982\u9700\u8d2d\u4e70 Cobalt Strike \u6216\u4e86\u89e3\u66f4\u591a\u4fe1\u606f\uff0c\u8bf7&nbsp;<a href=\"https:\/\/www.cobaltstrike.com\/quote-request\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u8054\u7cfb\u6211\u4eec<\/a>\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www.cobaltstrike.com\/blog\/cobalt-strike-4- [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[53,5,17],"tags":[54,135],"class_list":["post-556","post","type-post","status-publish","format-standard","hentry","category-cobalt-strike","category-infosec","category-infonews","tag-cobalt-strike","tag-socks5"],"views":2661,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/556","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=556"}],"version-history":[{"count":1,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/556\/revisions"}],"predecessor-version":[{"id":557,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/556\/revisions\/557"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}