unknown fe6dd776f5 small api fix 2 vuotta sitten
..
README.md 364a29c2f5 Update README.md 2 vuotta sitten
beacon.h db89d9b285 first commit 2 vuotta sitten
bofcompile.bat db89d9b285 first commit 2 vuotta sitten
finddotnet.c 66368f4738 small cleanup 2 vuotta sitten
finddotnet.cna 263c81c60d small fix 2 vuotta sitten
finddotnet.disasm fe6dd776f5 small api fix 2 vuotta sitten
finddotnet.h fe6dd776f5 small api fix 2 vuotta sitten
finddotnet.o fe6dd776f5 small api fix 2 vuotta sitten

README.md

FindDotnet

Find processes that most likely have .NET loaded by searching for the section name: \BaseNamedObjects\Cor_Private_IPCBlock(_v4)_<ProcessId>

Usage

  • finddotnet

Compile

  • 1. Make sure Visual Studio is installed and supports C/C++.
  • 2. Open the x64 Native Tools Command Prompt for VS <2019/2022> terminal.
  • 3. Run the bofcompile.bat script to compile the object file.
  • 4. In Cobalt strike, use the script manager to load the .cna script to import the tool.