BOF to run PE in Cobalt Strike Beacon without console creation
☆188Nov 23, 2025Updated 4 months ago
Alternatives and similar repositories for BOF_RunPe
Users that are interested in BOF_RunPe are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆65Dec 19, 2024Updated last year
- Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.☆186Dec 23, 2025Updated 3 months ago
- Sleep obfuscation☆271Dec 13, 2024Updated last year
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆189Jan 17, 2026Updated 2 months ago
- Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll☆151Apr 18, 2025Updated 11 months ago
- ☆100Sep 1, 2024Updated last year
- Execute commands, in/exfiltrate files using your custom RPC Server☆66Jan 13, 2026Updated 2 months ago
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆250Jun 11, 2024Updated last year
- Local SYSTEM auth trigger for relaying - X☆154Jul 23, 2025Updated 8 months ago
- A BOF that's a BOF Loader and more☆200Jan 17, 2026Updated 2 months ago
- A BOF that runs unmanaged PEs inline☆685Oct 23, 2024Updated last year
- 获取chrome 浏览器记录☆43Sep 6, 2025Updated 6 months ago
- ☆126Sep 1, 2024Updated last year
- Generic PE loader for fast prototyping evasion techniques☆245Jul 2, 2024Updated last year
- A BOF to create a scheduled task using a COM object.☆16Dec 3, 2024Updated last year
- Library of BOFs to interact with SQL servers☆227Dec 3, 2025Updated 3 months ago
- Reaping treasures from strings in remote processes memory☆285Feb 8, 2025Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆85Aug 13, 2024Updated last year
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆19Nov 11, 2025Updated 4 months ago
- ☆127Jan 23, 2025Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆301Jul 31, 2024Updated last year
- a BOF implementation of various registry persistence methods☆96Nov 11, 2025Updated 4 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆52Dec 4, 2023Updated 2 years ago
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆19Jun 20, 2025Updated 9 months ago
- UDC2 implementation that provides an ICMP C2 channel☆118Nov 24, 2025Updated 3 months ago
- SysCalling is an educational project demonstrating state-of-the-art syscall execution techniques for bypassing user-space EDR controls in…☆14Dec 8, 2024Updated last year
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆66Jan 5, 2026Updated 2 months ago
- ☆57Jan 15, 2024Updated 2 years ago
- Port of Cobalt Strike's Process Inject Kit☆192Dec 1, 2024Updated last year
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75May 1, 2024Updated last year
- User-Defined C2 BOF Template☆30Nov 24, 2025Updated 3 months ago
- BOF for Kerberos abuse (an implementation of some important features of the Rubeus).☆554Nov 23, 2025Updated 4 months ago
- One-header configurable C++20 COFF loader☆21Jul 21, 2025Updated 8 months ago
- ☆108Aug 21, 2024Updated last year
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆169Sep 22, 2025Updated 6 months ago
- Ghosting-AMSI☆228Apr 24, 2025Updated 10 months ago
- Fully functional, from-scratch alternative to the Cobalt Strike Beacon (red teaming tool), offering transparency and flexibility for secu…☆262Mar 13, 2024Updated 2 years ago
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆193Oct 29, 2025Updated 4 months ago
- early cascade injection PoC based on Outflanks blog post☆239Nov 7, 2024Updated last year