optiv / ScareCrow

ScareCrow - Payload creation framework designed around EDR bypass.
2.71k stars 503 forks source link

Output Types #70

Open gray-area opened 1 year ago

gray-area commented 1 year ago

What determines the output of ScareCrow? Can I manually adjust it? I cant seem to find what determines the output. Sometimes I get lync, word, excel, powerpoint, cmd and others, but I cant seem to get it to create the one I want, when I need it to. I know I am doing something wrong, I just dont know what it is. Any help is appreciated.

stevesec commented 1 year ago

Editing the Loaders/Loaders.go might help.

Tylous commented 1 year ago

So its designed to create them at random. I am currently working on a new version and that functionality can be added.