Skip to content

Instantly share code, notes, and snippets.

@jflyoo
Forked from MHaggis/Cobalt_Spawnto.csv
Created July 28, 2022 19:01
Show Gist options
  • Save jflyoo/53daf2a572fcc318ff946bd4fb2bc967 to your computer and use it in GitHub Desktop.
Save jflyoo/53daf2a572fcc318ff946bd4fb2bc967 to your computer and use it in GitHub Desktop.
Cobalt Strike Spawnto from June 2021 to present (July 2021)
x64_config_spawn_to_x64 count
%windir%\sysnative\RuntimeBroker.exe 2
%windir%\sysnative\WUAUCLT.exe 3
%windir%\sysnative\WerFault.exe 7
%windir%\sysnative\adobe64.exe 1
%windir%\sysnative\cmstp.exe 1
%windir%\sysnative\dllhost.exe 14
%windir%\sysnative\dllhost.exe -o enable 1
%windir%\sysnative\eventvwr.exe 1
%windir%\sysnative\gpresult.exe 2
%windir%\sysnative\gpupdate.exe 15
%windir%\sysnative\helloworld.exe 1
%windir%\sysnative\iexplore.exe 1
%windir%\sysnative\logman.exe 1
%windir%\sysnative\lsass.exe 2
%windir%\sysnative\msdt.exe 1
%windir%\sysnative\mstsc.exe 20
%windir%\sysnative\net.exe 1
%windir%\sysnative\prevhost.exe 3
%windir%\sysnative\regsvr32.exe 5
%windir%\sysnative\rundll32.exe 517
%windir%\sysnative\set-a-binary.exe 1
%windir%\sysnative\spoolsv.exe 3
%windir%\sysnative\svchost.exe 14
%windir%\sysnative\svchost.exe -k LocalService 1
%windir%\sysnative\svchost.exe -k NetworkService 1
%windir%\sysnative\svchost.exe -k netsvc 1
%windir%\sysnative\svchost.exe -k netsvcs 9
%windir%\sysnative\userinit.exe 1
%windir%\sysnative\w32tm.exe 3
%windir%\sysnative\wusa.exe 9
%windir%\system32\rundll32.exe 1
C:\Program Files\Internet Explorer\iexplore.exe 1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment