A Cobalt Strike Beacon Object File adaptation of BlueHammer that attempts to obtain a copy of the SAM database through Windows Defender update/VSS behavior and process offline registry data from Beacon.
Credits to Nightmare-Eclipse's BlueHammer (https://github.com/Nightmare-Eclipse/BlueHammer) for the original PoC.
- Git clone the repo
- Run
make
- Import the bluesam.cna script into Cobalt Strike
- Use the command
bluesam
bluesam
Command Description
(none) Runs the BlueSAM BOF with the default target behavior.
any argument Shows this help menu.