Skip to content
This repository has been archived by the owner on Sep 13, 2022. It is now read-only.

Minor modification for Visual Studio 2017 #1

Merged
merged 4 commits into from Aug 28, 2018
Merged

Minor modification for Visual Studio 2017 #1

merged 4 commits into from Aug 28, 2018

Conversation

ghost
Copy link

@ghost ghost commented Aug 28, 2018

There were a couple of issues on Windows 10 v1803 with Visual Studio 2017.

  1. Adjusted the Get-PEHeader.ps1 , GetProcAddress technique. Described here: https://blog.cobaltstrike.com/2018/05/24/powershell-shellcode-injection-on-win-10-v1803/

  2. Adjusted Out-Shellcode.ps1 to pattern match only on 'CODE' in the map file. This may not be optimal, but it worked. :)

Not sure if this is still maintained, so feel free to close and ignore

@mattifestation mattifestation merged commit 7f03be4 into mattifestation:master Aug 28, 2018
@mattifestation
Copy link
Owner

Thanks so much, @caseysmithrc!!!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant