Skip to content

Latest commit

 

History

History
17 lines (12 loc) · 895 Bytes

README.md

File metadata and controls

17 lines (12 loc) · 895 Bytes

Psm BOF

A BOF tool that can be used to show detailed information from a specific process id (loaded modules, tcp connections e.g.).

How to compile

  1. Make sure that Mingw-w64 (including mingw-w64-binutils) has been installed.
  2. Enter the SOURCE folder within the tool folder.
  3. Type "make" to compile the object files.
  4. Use Cobal Strike script manager to import the Psm.cna script.

Usage

Running the tools is straightforward. Once you imported the CNA script using Cobalt Strike's Script Manager, they are available as Cobalt Strike commands that can be executed within a beacon. This tools supports the following commands:

  • psm [processid]

Support

This BOF tool has been successfully compiled on Mac OSX systems and used on Windows 8.1+ (x64) systems. Compiling the BOF code should also work on other systems (Linux, Windows) that have the Mingw-w64 compiler installed.