Und3rf10w / CobaltStrikeBOFs
Beacon Object Files used for Cobalt Strike
☆17Updated last year
Alternatives and similar repositories for CobaltStrikeBOFs:
Users that are interested in CobaltStrikeBOFs are comparing it to the libraries listed below
- A simple rpc2socks alternative in pure Go.☆28Updated 7 months ago
- ☆16Updated 10 months ago
- .NET port of Leron Gray's azbelt tool.☆26Updated last year
- ManageEngine ADManager Command Injection☆12Updated last year
- freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package☆34Updated last year
- Extension functionality for the NightHawk operator client☆26Updated last year
- ☆18Updated 4 months ago
- Yet, Another Packer/Loader☆25Updated last year
- ☆21Updated last year
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 8 months ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆20Updated last year
- Example of using Sleep to create better named pipes.☆41Updated last year
- Cobalt Strike notifications via NTFY.☆13Updated 4 months ago
- OSED Practice binary☆24Updated last year
- An adaptation of timwhitez's proxycall that uses kernelbase.dll!Beep.☆12Updated last year
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- ☆17Updated 2 months ago
- Python3 tool to perform password spraying using RDP☆16Updated last year
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆19Updated last year
- ShootCutMe an .LNK file creator tool for redteamer☆13Updated 4 months ago
- Giga-byte Control Center (GCC) is a software package designed for improved user experience of Gigabyte hardware, often found in gaming an…☆31Updated last year
- This repository contains several AMSI bypasses. These bypasses are based on some very nice research that has been put out by some awesome…☆23Updated 2 years ago
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆18Updated last year
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆30Updated last year
- A simple to use single-include Windows API resolver☆19Updated 7 months ago
- Watches the Downloads folder for any new files and inserts it into Nemesis for analysis.☆14Updated 11 months ago
- Remotely dump NT hashes through Windows Crash dumps☆26Updated 3 months ago
- All my POC related to malware development☆11Updated 9 months ago
- ☆46Updated 2 years ago
- string encryption in Nim☆17Updated 8 months ago