Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.
☆88Jul 20, 2026Updated this week
Alternatives and similar repositories for Offensive-COM
Users that are interested in Offensive-COM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆89Updated this week
- ☆51Jul 12, 2026Updated last week
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jun 15, 2026Updated last month
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- open source implementation of the UDC2 spec used in Cobalt Strike☆55Jul 4, 2026Updated 2 weeks ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆219Jan 6, 2026Updated 6 months ago
- CVE-2026-50416: Windows 11 KASLR bypass☆28Updated this week
- ☆23May 19, 2026Updated 2 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 6 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated last month
- Enumerate Domain Users Without Authentication☆304Apr 22, 2025Updated last year
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆98Apr 30, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Updated this week
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- Cobalt Strike BOF to obtain location data☆26Jul 4, 2026Updated 2 weeks ago
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 8 months ago
- Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler☆19Jul 2, 2026Updated 2 weeks ago
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated last month
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 2 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆70Jul 11, 2026Updated last week
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 3 months ago
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 2 months ago
- A BOF that's a BOF Loader and more☆209Apr 6, 2026Updated 3 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆191Apr 27, 2026Updated 2 months ago
- WhatAboutSAM is my custom PoC of a Windows SAM dumper☆37Jul 4, 2026Updated 2 weeks ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 4 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆155Updated this week
- Evasive loader for .NET Framework assemblies☆82May 12, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆62May 4, 2026Updated 2 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆273Jun 22, 2026Updated 3 weeks ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Updated this week
- Abusing the win32k.sys kernel callback mechanism for arbitrary code execution☆106Apr 10, 2026Updated 3 months ago
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆220Feb 16, 2026Updated 5 months ago
- ☆192Oct 21, 2025Updated 8 months ago
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆176Jul 10, 2026Updated last week