Cobalt-Strike/Artifact-Kit

From aldeid
Jump to navigation Jump to search
You are here
Artifact Kit

Description

  • What is the Artifact Kit?
    • Source code framwork to generate EXEs, DLLs and Service EXEs
    • Go to Help -> Arsenal to download Artifact Kit (requires a licensed version of Cobalt Strike)
  • How it works
    • Obfuscate known bad in unknown executable
    • Fool AV product to stop emulating executable
    • De-obfuscate known bad and execute it