Posts: 2,884
Threads: 65
Joined: Jun 2024
Jul 25, 2024, 08:10 PM
(This post was last modified: Jul 25, 2024, 08:13 PM by Loki.)
Goffloader is a library that allows easy in-memory execution of Cobalt Strike BOFs and unmanaged PE files.
Given that there's already a number of very excellent C implementations of this functionality, why do this in Go?
Quote:Adding BOF loading to Go expands the number of open source security projects that can be used within Go security tooling. There are entire repositories of useful functionality that are now accessible for Go tools via this library.
While you can technically just use a C implementation of COFF loaders (Sliver does this, for example), CGO is annoying.
Go is a nice language for static signature evasion. You can see an example of us being able to run an embedded version of mimikatz without jumping through too many hoops.
Limitations
Quote:Currently the COFFLoader implementation is only for x64 architecture. 32-bit support will be coming soon.
At the moment the PE execution is just loading a BOF with hard-coded arguments - eventually a few different approaches will be supported.
The Beacon* API implementation is partial - most BOFs don't use much beyond the arg parsing + output functions, but there's a chunk of beacon.h which still needs to be implemented. This will be done as useful BOFs are identified that rely on these APIs.
Using this library in its current state will NOT generate a 0/N detections file on VT. Right now it's 2 or 3 detections from the usual offender false+ mills, but users should be aware of this.
Posts: 7
Threads: 0
Joined: Aug 2024
Posts: 47
Threads: 4
Joined: May 2024
(Jul 25, 2024, 08:10 PM)Loki Wrote: Goffloader is a library that allows easy in-memory execution of Cobalt Strike BOFs and unmanaged PE files.
Given that there's already a number of very excellent C implementations of this functionality, why do this in Go?
Quote:Adding BOF loading to Go expands the number of open source security projects that can be used within Go security tooling. There are entire repositories of useful functionality that are now accessible for Go tools via this library.
While you can technically just use a C implementation of COFF loaders (Sliver does this, for example), CGO is annoying.
Go is a nice language for static signature evasion. You can see an example of us being able to run an embedded version of mimikatz without jumping through too many hoops.
Limitations
Quote:Currently the COFFLoader implementation is only for x64 architecture. 32-bit support will be coming soon.
At the moment the PE execution is just loading a BOF with hard-coded arguments - eventually a few different approaches will be supported.
The Beacon* API implementation is partial - most BOFs don't use much beyond the arg parsing + output functions, but there's a chunk of beacon.h which still needs to be implemented. This will be done as useful BOFs are identified that rely on these APIs.
Using this library in its current state will NOT generate a 0/N detections file on VT. Right now it's 2 or 3 detections from the usual offender false+ mills, but users should be aware of this.
is this BOF loader for some kind of stage 1 C2? or this is for CS directly? This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Malware. /Thread-Shellter-Pro-v4-7-x86-NOT-WORKING-crack
Posts: 149
Threads: 4
Joined: Sep 2023
(Jul 25, 2024, 08:10 PM)Loki Wrote: Goffloader is a library that allows easy in-memory execution of Cobalt Strike BOFs and unmanaged PE files.
Given that there's already a number of very excellent C implementations of this functionality, why do this in Go?
Quote:Adding BOF loading to Go expands the number of open source security projects that can be used within Go security tooling. There are entire repositories of useful functionality that are now accessible for Go tools via this library.
While you can technically just use a C implementation of COFF loaders (Sliver does this, for example), CGO is annoying.
Go is a nice language for static signature evasion. You can see an example of us being able to run an embedded version of mimikatz without jumping through too many hoops.
Limitations
Quote:Currently the COFFLoader implementation is only for x64 architecture. 32-bit support will be coming soon.
At the moment the PE execution is just loading a BOF with hard-coded arguments - eventually a few different approaches will be supported.
The Beacon* API implementation is partial - most BOFs don't use much beyond the arg parsing + output functions, but there's a chunk of beacon.h which still needs to be implemented. This will be done as useful BOFs are identified that rely on these APIs.
Using this library in its current state will NOT generate a 0/N detections file on VT. Right now it's 2 or 3 detections from the usual offender false+ mills, but users should be aware of this.
enter chinese apt
Posts: 7
Threads: 0
Joined: Sep 2024
qwerwerqwerqweqweqweqweqweqweqweqwe
Posts: 11
Threads: 0
Joined: Oct 2024
Posts: 39
Threads: 0
Joined: Jul 2024
will check this This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 2
Threads: 0
Joined: Jan 2025
Posts: 14
Threads: 0
Joined: Mar 2025
thanks lets see how it is
Posts: 2
Threads: 0
Joined: Jul 2025
|