Patrick0x41 / BOF_All_Things
Beacon Object Files (BOF) for Cobalt Strike.
☆28Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for BOF_All_Things
- DFSCoerce exe revisited version with custom authentication☆36Updated 10 months ago
- ☆28Updated 5 months ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- ☆46Updated last year
- BOF for C2 framework☆40Updated last week
- ☆10Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆42Updated 3 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆73Updated last month
- ☆79Updated 6 months ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 6 months ago
- Lateral Movement via the .NET Profiler☆76Updated 5 months ago
- Contexter - A secondary context path traversal / server-side parameter pollution testing tool written in Python 3☆20Updated 3 months ago
- ☆47Updated last year
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆37Updated 10 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆88Updated 9 months ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated 10 months ago
- ☆26Updated 3 months ago
- HEVD Exploit: ArbitraryWrite on Windows 10 22H2 - Bypassing KVA Shadow and SMEP via PML4 Entry Manipulation☆15Updated 4 months ago
- Beacon Object Files (not Buffer Overflows)☆51Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 5 months ago
- Sniffing files generator☆38Updated this week
- Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute☆19Updated 5 months ago
- Proof of Concept Exploit for CVE-2024-9465☆25Updated last month
- A third-party Gopher Assassin for the Havoc Framework.☆44Updated 10 months ago
- A simple rpc2socks alternative in pure Go.☆24Updated 4 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆23Updated 2 months ago
- Click Once + App Domain☆62Updated 11 months ago
- ☆59Updated 3 months ago
- A care package of useful bofs for red team engagments☆48Updated 2 years ago