Blog | G5 Cyber Security

Dont Be Rude, Stay: Avoiding Fork&Run .NET Execution With InlineExecute-Assembly

Beacon Object File (BOF) allows operators to execute.NET assemblies in process via Cobalt Strike versus the traditional built-in execute-assembly module, which uses the fork and run technique. This blog will dive into why I wrote the BOF, some of its key features, caveats, and how it could be useful when conducting adversary simulations/red teams. InlineExecute-Assembly can be used to execute.NET assemblies inside your beacon process with no modification to your favorite.NET tooling.”]

Source: https://securityintelligence.com/posts/net-execution-inlineexecute-assembly/

Exit mobile version