chryzsh / awesome-bofLinks
š§ The ultimate, community-curated resource for Beacon Object Files (BOFs) ā tutorials, how-tos, deep dives, and reference materials.
ā95Updated last month
Alternatives and similar repositories for awesome-bof
Users that are interested in awesome-bof are comparing it to the libraries listed below
Sorting:
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspectiveā164Updated 2 weeks ago
- ForsHopsā152Updated 10 months ago
- adws enumeration bofā161Updated 3 months ago
- ā137Updated 2 months ago
- Lateral Movement Bof with MSI ODBC Driver Installā141Updated 4 months ago
- ā125Updated last month
- A hoontr must hoontā103Updated 2 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.ā113Updated 2 weeks ago
- Lateral movement with DCOM DLL hijackingā176Updated 6 months ago
- Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)ā128Updated 3 months ago
- One WSL BOF to rule them allā119Updated 2 weeks ago
- Evasive Payload Delivery Server & C2 Redirectorā112Updated 2 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+Sā¦ā112Updated last month
- Local SYSTEM auth trigger for relayingā167Updated 6 months ago
- .NET assembly loader with patchless AMSI and ETW bypass in Rustā58Updated last year
- ā143Updated 2 months ago
- ā123Updated last year
- Bypass user-land hooks by syscall tampering via the Trap Flagā138Updated 5 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.ā99Updated 3 weeks ago
- Internal Monologue BOFā79Updated last year
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.ā200Updated 3 weeks ago
- A python script that automates a C2 Profile buildā48Updated last month
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpointsā121Updated 6 months ago
- Stage 0ā169Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to executionā194Updated last year
- ā138Updated last year
- Local SYSTEM auth trigger for relaying - Xā155Updated 6 months ago
- A tool for coercing and relaying Kerberos authentication over DCOM and RPC.ā146Updated 6 months ago
- Collection of BOFs created for red team/adversary engagements. Created to be small and interchangeable, for quick recon or eventing.ā228Updated last week
- ā37Updated 2 months ago