
William Knowles
@william_knows


Iām going to really enjoy presenting this with William Knowles blogs.technet.microsoft.com/bluehat/2018/0⦠#Microsoft #BlueHat v18.


Finally got round to releasing part two. Thought Iād use the excellent GhostPack by SpecterOps/Will Schroeder as an example countercept.com/blog/detectingā¦

About to head to #BlueHatv18. If youāre around, do come along to hear myself & William Knowles from MWR Infosecurity mwrlabs talk about āOvert C2: The Art of Blending Inā on Thursday at 16:10 PM. There will be demos of new shiny #RedTeam tooling C3 \0/



Very happy to say I'll be presenting at TROOPERS Conference #TR19 along with my colleague James Coote this coming March. The topic will be practical attack simulations in industrial environments.





Porting existing .NET projects for use with the fantastic BOFNET from CCobš“ó §ó ¢ó ·ó ¬ó ³ó æ (in-process .NET assembly execution in Cobalt Strike for when you need to avoid fork and run). williamknowles.io/quickly-portinā¦

bofnet_executeassembly - integrating in-process standard .NET assembly execution into BOF.NET. No modifications to executed assemblies required (unlike my last tweet). Thanks CCobš“ó §ó ¢ó ·ó ¬ó ³ó æ for pointing me in the right direction! github.com/CCob/BOF.NET/pā¦



