Update README.md

This commit is contained in:
Bobby Cooke
2023-02-24 07:23:25 -07:00
committed by GitHub
parent d75cb363de
commit 0dcd44b707
+2 -2
View File
@@ -1,8 +1,8 @@
# BokuLoader : Cobalt Strike Reflective Loader
A proof-of-concept [Cobalt Strike](https://www.cobaltstrike.com/) Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
A proof-of-concept Cobalt Strike [User-Defined Reflective Loader (UDRL)](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/malleable-c2-extend_user-defined-rdll.htm) which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
## UDRL Usage Considerations
The built-in Cobalt Strike reflective loader is robust, handling all [Malleable PE evasion features](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/malleable-c2-extend_pe-memory-indicators.htm) Cobalt Strike has to offer. The major disadvantage to using a [custom User-Defined Reflective Loader (UDRL)](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/malleable-c2-extend_user-defined-rdll.htm) is Malleable PE evasion features may or may not be supported out-of-the-box.
The built-in [Cobalt Strike](https://www.cobaltstrike.com/) reflective loader is robust, handling all [Malleable PE evasion features](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/malleable-c2-extend_pe-memory-indicators.htm) Cobalt Strike has to offer. The major disadvantage to using a custom UDRL is Malleable PE evasion features may or may not be supported out-of-the-box.
The objective of the public BokuLoader project is to function as a blueprint for red teams seeking to create their own in-house Cobalt Strike UDRL. The project aims to support all worthwhile CS Malleable PE evasion features. Some evasion features leverage CS integration, others have been recreated completely, and some are unsupported.