当前位置:网站首页>Cobalt Strike安装教程
Cobalt Strike安装教程
2022-06-24 20:21:00 【小胡yhu】
CobaltStrike
CobaltStrike是一款渗透测试神器,被业界人称为CS神器。CobaltStrike分为客户端与服务端,服务端是一个,客户端可以有多个,可被团队进行分布式协团操作。
CobaltStrike集成了端口转发、服务扫描,自动化溢出,多模式端口监听,windows exe 木马生成,windows dll 木马生成,java 木马生成,office 宏病毒生成,木马捆绑。钓鱼攻击包括:站点克隆,目标信息获取,java 执行,浏览器自动攻击等等强大的功能!
Cobaltstrike teamserver的启动:
开启Cobaltstrike teamserver和运行GUI界面均需要Java环境,电脑上必须把Java装好,自行百度。
解压之后,看到文件中有这几个文件。
直接运行
./teamserver 192.168.1.115 12345678
192.168.1.115 //网卡IP地址
12345678 //密码
启动客户端
# ./start.sh
这里host填kali的ip,密码就是刚刚我们启动的密码,用户名默认neo就行,端口也是默认50050。
启动后的客户端:
CobaltStrike的使用
CobaltStrike模块
· New Connection:打开一个新连接窗口
· Preferences:偏好设置,就是设置CobaltStrike外观的
· Visualization:将主机以不同的权限展示出来(主要以输出结果的形式展示)
· VPN Interfaces:设置VPN接口
· Listeners:创建监听器
· Script Interfaces:查看和加载CNA脚本
· Close:关闭
cobaltstrike
设置监听器
设置Attack
寻找靶机漏洞,执行命令
靶机上线
提权
边栏推荐
- redis + lua实现分布式接口限流实现方案
- Can communication experiment between C and C
- Scala sample class case calculate
- 【Redis实现秒杀业务③】超卖问题之乐观锁具体实现
- Golang示例续期锁:Redis+Channel+sync.Mutex
- Usage of assert
- A small crawler program written by beginners
- Text editor for QT project practice - Episode 10
- C#和C 的CAN通信实验
- ServerSocket and socket connection
猜你喜欢

Examination questions and mock examination for safety management personnel of hazardous chemical business units in 2022

Usage of ViewModel and livedata in jetpack

Punch smart spirit 1. The brand is attractive. What is the strength of the product?

The acceleration of 100 km is only 5.92 seconds, and the willanda high-performance version leads with the strength of high-energy products

2022R1快开门式压力容器操作考题及答案

【Redis实现秒杀业务③】超卖问题之乐观锁具体实现

Custom control - round dot progress bar (imitating one key acceleration in security guard)

Network request -volley

Single blind box removal, social blind box and friend blind box program source code

The basic principle and application of iterator and enhanced for
随机推荐
断言(assert)的用法
JSON file of China's provincial boundaries
Mobile security tool jar
EVM Brief
2022 melting welding and thermal cutting recurrent training question bank simulated examination platform operation
redis + lua实现分布式接口限流实现方案
Text editor of QT project practice ---------- episode 11
生成订单30分钟未支付,则自动取消,该怎么实现?
Scala responsibility chain pattern
Thingsboard - rest API obtains and refreshes tokens
QT(36)-rapidjson解析嵌套的json
Only positive integers can be entered in the text box
移动安全工具-jarsigner
实现mnist手写数字识别
2022年全国最新消防设施操作员(高级消防设施操作员)模拟题及答案
QT (36) -rapidjson parsing nested JSON
图书馆管理系统代码源码(php+css+js+mysql) 完整的代码源码
adb shell getevent
I'd like to ask how to open an account at industrial securities? Is it safe to open a stock account through the link
【微服务|Sentinel】实时监控|RT|吞吐量|并发数|QPS