Implemented 'dotnet' command for execute-assembly functionality. Patched AMSI using HWBP

This commit is contained in:
Jakob Friedl
2025-09-13 11:47:19 +02:00
parent 9b94a06ce9
commit 94f2f8121c
10 changed files with 338 additions and 27 deletions

View File

@@ -31,7 +31,7 @@ Execution Commands
- Read from listener endpoint directly to memory
- Base for all kinds of BOFs (Situational Awareness, ...)
- [ ] pe : Execute PE file in memory and retrieve output (pe /local/path/mimikatz.exe)
- [ ] dotnet : Execute .NET assembly inline in memory and retrieve output (dotnet /local/path/Rubeus.exe )
- [x] dotnet : Execute .NET assembly inline in memory and retrieve output (dotnet /local/path/Rubeus.exe )
Post-Exploitation
-----------------