KaynStrike
A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.
Thread Start Address spoofing
Reflective Loader cleanup
Proof
How to use this
Just load the KaynStrike.cna
agressor script and build a stageless beacon (tested this as an exe)
Credits
- S4ntiagoP. Had the idea from one of his tweets to free the reflective loader
- Austin Hudson (aka SecIdiot). Reflective Loader Design & ROP Chain