Skip to content

rasta-mouse/Crystal-Loaders

Repository files navigation

Crystal Loaders

This repo contains a couple of PIC loaders and a custom sleepmask COFF for use with Cobalt Strike. They are basic implementations where custom evasion tradecraft must be weaved in using Crystal Palace.

Usage

  1. Download the Crystal Palace Release distrubtion.
  2. Extract the tar archive and copy crystalpalace.jar to the same directory as cobaltstrike.exe (the client).
  3. Load loaders.cna to use the custom loaders (there are loaders for both Beacon and postex DLLs).
  4. Load mask.cna to use the custom sleepmask.

Notes

You can use just the loaders, just the sleepmask, or both together. Each are compatible with the 4.12 BUD structures, so in theory, you can mix and match these with other custom loaders and sleepmasks (assuming they are also 4.12-compatible). This project is not backwards-compatible with pre-4.12.

About

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages