The Veil Evasion Framework
Veil is a popular framework to generate executables that get past some anti-virus products. You may use Veil to generate executables for Cobalt Strike’s payloads.
Steps
- Go to Payloads -> Stager Payload Generator.
- Choose the listener you want to generate an executable for.
- Select Veil as the Output type.
- Press Generate and save the file.
- Launch the Veil Evasion Framework and choose the technique you want to use.
- Veil will eventually ask about shellcode. Select Veil’s option to supply custom shellcode.
-
Paste in the contents of the file Cobalt Strike’s payload generator made.
-
Press enter and you will have a fresh Veil-made executable.
figure 52 - Using Veil to Generate an Executable