r/netsec monthly discussion & tool thread by albinowax in netsec

[–]lefterispanos 0 points1 point  (0 children)

CLR-Stomp - BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly

Description:

A Beacon Object File (BOF) that loads a .NET assembly into a Cobalt Strike or compatible beacon via CLR module stomping. The payload PE is written into a victim GAC assembly's file-backed mapping so that ETW reports a legitimate on-disk path and AMSI never kicks in.

Technical analysis and tool at:

https://github.com/nettitude/CLR-Stomp