An Aggressor Script that utilizes NtCreateUserProcess to run binaries
☆32Jan 30, 2025Updated last year
Alternatives and similar repositories for NtCreateUserProcessBOF
Users that are interested in NtCreateUserProcessBOF are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- use python on windows with full submodule support without installation☆31Jan 23, 2025Updated last year
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆66Mar 19, 2024Updated 2 years ago
- Shellcode Loader Utilizing ETW Events☆66Feb 26, 2025Updated last year
- Repository to gather the BOF files I will be developing☆12Oct 1, 2024Updated last year
- Reaping treasures from strings in remote processes memory☆289Feb 8, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- converts sRDI compatible dlls to shellcode☆39Jan 20, 2025Updated last year
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆195Jan 17, 2026Updated 7 months ago
- Yet another C++ Cobalt Strike beacon dropper with Compile-Time API hashing and custom indirect syscalls execution☆203May 29, 2025Updated last year
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆132Jul 11, 2025Updated last year
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 9 months ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆89Jan 6, 2023Updated 3 years ago
- BOF to decrypt Signal Desktop chat logs☆70Feb 20, 2025Updated last year
- Post-Ex BOF tooling for Hannibal☆25Nov 20, 2024Updated last year
- Mythic C2 Agent written in x64 PIC C☆86Jan 29, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Position-independent Reflective Loader for macOS☆132Feb 19, 2026Updated 6 months ago
- A care package of useful bofs for red team engagments☆53Dec 6, 2024Updated last year
- ☆152Nov 6, 2025Updated 9 months ago
- BOF with Synthetic Stackframe☆260Oct 30, 2025Updated 9 months ago
- remote process injections using pool party techniques☆73Jun 29, 2025Updated last year
- Rust template/library for implementing your own COFF loader☆71Jan 27, 2025Updated last year
- External C2 is a specification to allow third-party programs to act as a communication layer for Cobalt Strike’s Beacon payload.☆22Jul 17, 2025Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆40Jul 12, 2024Updated 2 years ago
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated 11 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Port of Cobalt Strike's Process Inject Kit☆195Dec 1, 2024Updated last year
- ☆113Feb 17, 2025Updated last year
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆60Feb 29, 2024Updated 2 years ago
- Modified versions of the Cobalt Strike Process Injection Kit☆110Jan 24, 2024Updated 2 years ago
- early cascade injection PoC based on Outflanks blog post, in rust☆64Nov 8, 2024Updated last year
- An example reference design for a proposed BOF PE☆245Jan 23, 2026Updated 7 months ago
- Malware dev tricks. Syscalls part 1. Simple C example☆11Jun 8, 2023Updated 3 years ago
- ☆129Jun 28, 2023Updated 3 years ago
- ☆29May 10, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A New Exploitation Technique for Visual Studio Projects☆13Nov 5, 2023Updated 2 years ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆186May 17, 2023Updated 3 years ago
- Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options☆166Mar 26, 2025Updated last year
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆27Apr 20, 2026Updated 4 months ago
- Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll☆155Apr 18, 2025Updated last year
- ☆59Jan 9, 2023Updated 3 years ago
- A collection of position independent coding resources☆129Nov 15, 2025Updated 9 months ago