ScareCrow Versions Save

ScareCrow - Payload creation framework designed around EDR bypass.

v2.1

2 years ago

Bug Fixes


  • Fixed Mshta delivery implant issue.

v2.0

2 years ago

New Features


  • Introduced ETW bypass mechanisms to prevent ETW events from being generated.
  • Introduced unhooked process Injection techniques to unhook an EDR from the injected process.
  • Added a flag to allow a custom set of JSON for Attribute Spoofing.
  • Add a new list of DLLs for the WScript loader option.
  • Added anti-attribution controls in binary mode.

Bug Fixes


  • Fixed some command line bugs.
  • Updated help menu & README.

v1.5

3 years ago

Bug Fixes


  • Fixed error with delivery commands 'htaandbits` that prevented the one-line command from displaying.
  • Added in additional controls to allow certain types of loaders to be used with certain delivery commands (to prevent incompatibilities)
  • Updated help menu & README to indicate which delivery commands work well with what loaders

v1.4

3 years ago

Bug Fixes


  • Fixed bug with compiling binary loaders on new versions of Go

v1.3

3 years ago

Bug Fixes


  • Replaced SSL code signing "runtime error" with a proper error message and clean-up command.
  • Updated help menu & README

v1.2

3 years ago

New Features


  • Added the ability to create standalone CPL files with no loader

Bug Fixes


  • Fixed "Revocation Issue" for Certain Sensors
  • Updated help menu & README