Skip to content

主要用于隐藏进程真实路径,进程带windows真签名

Notifications You must be signed in to change notification settings

qigpig/Ghosting-BOF

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Ghosting BOF

主要用于隐藏进程真实路径,进程带windows真签名

加载cna后,用gosting "path" "parameters" 运行你想要的程序:

image1

使用火绒剑查看相关进程信息:

image2

进程对应文件hash一致:

image3

自行套用bof-vs进行编译,MinGW版等空了再加上去(https://github.com/Cobalt-Strike/bof-vs)

关注我: ads

About

主要用于隐藏进程真实路径,进程带windows真签名

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages