chryzsh / awesome-bof
🧠 The ultimate, community-curated resource for Beacon Object Files (BOFs) — tutorials, how-tos, deep dives, and reference materials.
☆65Updated 2 weeks ago
Alternatives and similar repositories for awesome-bof:
Users that are interested in awesome-bof are comparing it to the libraries listed below
- ForsHops☆126Updated last month
- ☆114Updated last month
- AzureAD beacon object files☆118Updated 4 months ago
- ☆109Updated 3 months ago
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆95Updated last month
- ☆40Updated this week
- Two in one, patch lifetime powershell console, no more etw and amsi!☆88Updated 2 weeks ago
- Adversary Emulation Framework☆98Updated 9 months ago
- A python script that automates a C2 Profile build☆40Updated last month
- The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning☆112Updated last month
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- Impersonate Tokens using only NTAPI functions☆71Updated last month
- ☆154Updated 9 months ago
- ☆106Updated 3 months ago
- A Mythic agent for Windows written in C☆121Updated 2 weeks ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆158Updated last month
- .NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCS☆143Updated 3 months ago
- ☆126Updated 8 months ago
- A web assembly (WASM) phishing lure generator based on pre-built templates and written in Rust with some GenAI assistance. W.A.L.K. aims …☆82Updated 8 months ago
- BOF with Synthetic Stackframe☆145Updated 2 months ago
- a port of privkit bof for havoc☆23Updated last year
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆121Updated 7 months ago
- ☆106Updated 2 months ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆97Updated last year
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆156Updated 2 weeks ago
- ☆44Updated last month
- .NET assembly loader with patchless AMSI and ETW bypass in Rust☆48Updated 7 months ago
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆75Updated 2 months ago
- ☆80Updated 9 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆74Updated 8 months ago