Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.
☆153Jul 20, 2026Updated 3 weeks ago
Alternatives and similar repositories for Offensive-COM
Users that are interested in Offensive-COM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆112Jul 14, 2026Updated 3 weeks ago
- ☆59Jul 12, 2026Updated 3 weeks ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆58Jul 4, 2026Updated last month
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆197Apr 27, 2026Updated 3 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated 2 weeks ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Jul 23, 2026Updated 2 weeks ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated last month
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 3 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆158Jul 15, 2026Updated 3 weeks ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated 2 weeks ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆69Jul 14, 2026Updated 3 weeks ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 3 months ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated 2 weeks ago
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆220Jan 6, 2026Updated 7 months ago
- ☆23May 19, 2026Updated 2 months ago
- Set of PoC to abuse Windows minifilters functionality☆94May 1, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Abusing the win32k.sys kernel callback mechanism for arbitrary code execution☆110Apr 10, 2026Updated 4 months ago
- Enumerate Domain Users Without Authentication☆306Apr 22, 2025Updated last year
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆246Updated this week
- Cobalt Strike BOF to obtain location data☆30Jul 4, 2026Updated last month
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 7 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- ☆194Oct 21, 2025Updated 9 months ago
- Activation Context Hijacking Evasion Tool☆306Jun 17, 2026Updated last month
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆283Jun 22, 2026Updated last month
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆142Jan 28, 2026Updated 6 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆195Jan 17, 2026Updated 6 months ago
- A Crystal Palace shared library to resolve & perform syscalls☆66Oct 29, 2025Updated 9 months ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- A Payload Analysis Framework☆122Oct 9, 2025Updated 10 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆362Updated this week