☆57Jan 15, 2024Updated 2 years ago
Alternatives and similar repositories for obfuscator-llvm
Users that are interested in obfuscator-llvm are comparing it to the libraries listed below
Sorting:
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆49Mar 15, 2023Updated 2 years ago
- BypassCredGuard CS BOF☆51Jan 23, 2025Updated last year
- ☆101Oct 7, 2023Updated 2 years ago
- A swiss army knife tool for running, injecting and organizing your BOFs collection☆73Feb 20, 2026Updated last week
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆31Feb 11, 2021Updated 5 years ago
- Generic PE loader for fast prototyping evasion techniques☆244Jul 2, 2024Updated last year
- ☆129Jun 28, 2023Updated 2 years ago
- ☆123Oct 9, 2023Updated 2 years ago
- Cobalt Strike User Defined Reflective Loader (UDRL). Check branches for different functionality.☆151Jul 20, 2022Updated 3 years ago
- A simple BOF that frees UDRLs☆122May 29, 2022Updated 3 years ago
- An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are a…☆139Oct 1, 2022Updated 3 years ago
- Hardened Proof of Concept of D/Invoke Process Injection malware☆42Jul 23, 2020Updated 5 years ago
- POC tool to convert CobaltStrike BOF files to raw shellcode☆220Nov 5, 2021Updated 4 years ago
- ☆24Feb 1, 2025Updated last year
- ☆83Nov 1, 2023Updated 2 years ago
- Files for http://blog.deniable.org/posts/windows-callbacks/☆12Jan 1, 2023Updated 3 years ago
- An example reference design for a proposed BOF PE☆200Jan 23, 2026Updated last month
- Code for blog written at 0xdarkvortex.dev Red Team TTPs Part 2☆19Oct 8, 2020Updated 5 years ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆186Nov 23, 2025Updated 3 months ago
- ☆60Jan 9, 2023Updated 3 years ago
- Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.☆147Sep 8, 2022Updated 3 years ago
- A BOF that runs unmanaged PEs inline☆681Oct 23, 2024Updated last year
- ☆94May 14, 2022Updated 3 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆675Aug 15, 2025Updated 6 months ago
- ☆153Jan 6, 2023Updated 3 years ago
- ☆31Jul 26, 2024Updated last year
- ☆29May 10, 2024Updated last year
- ☆615Jul 21, 2025Updated 7 months ago
- InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assem…☆741Jul 22, 2023Updated 2 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆1,006Jun 4, 2024Updated last year
- A lexer and parser for Sleep☆20Feb 20, 2026Updated last week
- ☆125Jun 28, 2023Updated 2 years ago
- A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk☆473Jul 6, 2024Updated last year
- DLL Exports Extraction BOF with optional NTFS transactions.☆90Nov 5, 2021Updated 4 years ago
- ☆79Aug 5, 2024Updated last year
- POC for NetworkService PrivEsc☆130May 4, 2020Updated 5 years ago
- Collection of Beacon Object Files☆633Nov 1, 2022Updated 3 years ago
- An App Domain Manager Injection DLL PoC on steroids☆212Dec 14, 2023Updated 2 years ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆324Jan 17, 2024Updated 2 years ago