Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintain stealth and robust OPSEC.
☆80Oct 27, 2025Updated 6 months ago
Alternatives and similar repositories for SafeHarbor-BOF
Users that are interested in SafeHarbor-BOF are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Powershell and python utilties for Entra Connect☆29Jun 5, 2025Updated 10 months ago
- Python script to leverage MSFT_MTProcess WMI class☆40Sep 17, 2025Updated 7 months ago
- UDC2 implementation that provides an ICMP C2 channel☆123Nov 24, 2025Updated 5 months ago
- Leveraging AWS Lambda Function URLs for C2 Redirection☆47Aug 30, 2023Updated 2 years ago
- Updated version of a long known self deletion technique to work with 24H2.☆62Jun 9, 2025Updated 10 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆125Mar 27, 2026Updated last month
- Docker container for running CobaltStrike 4.7 and above☆25Mar 20, 2025Updated last year
- An example reference design for a proposed BOF PE☆206Jan 23, 2026Updated 3 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆129Jan 17, 2026Updated 3 months ago
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆69Jan 5, 2026Updated 3 months ago
- ☆24Feb 1, 2025Updated last year
- ☆18Jun 25, 2024Updated last year
- BOF and C++ implementation of the Windows Defender sandboxing technique described by Elastic Security Labs/Gabriel Landau.☆25Jul 5, 2023Updated 2 years ago
- ☆50Jun 4, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons☆206Feb 11, 2026Updated 2 months ago
- ☆38Dec 4, 2025Updated 5 months ago
- Proof-of-concept implementation of AI-enabled postex DLLs☆90Sep 10, 2025Updated 7 months ago
- ☆55Jun 28, 2025Updated 10 months ago
- ☆18Feb 29, 2024Updated 2 years ago
- ☆39Feb 26, 2025Updated last year
- Tools for attacking Computer Use Agents☆30Jan 16, 2026Updated 3 months ago
- ☆26Mar 24, 2026Updated last month
- ☆100Sep 1, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Enable EFS service as low priv user (PE & BOF)☆21Jul 6, 2025Updated 9 months ago
- A BOF that's a BOF Loader and more☆203Apr 6, 2026Updated 3 weeks ago
- ☆139Nov 17, 2025Updated 5 months ago
- Test bench lab for Shellcode Obfuscation☆36Sep 2, 2025Updated 8 months ago
- ☆83Nov 1, 2023Updated 2 years ago
- ☆50Dec 5, 2025Updated 4 months ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Apr 14, 2025Updated last year
- The DCERPC only printerbug.py version☆219Oct 30, 2025Updated 6 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆133Jan 28, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆52May 4, 2025Updated last year
- CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking☆287Jun 8, 2023Updated 2 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆687Aug 15, 2025Updated 8 months ago
- Strstr with user-supplied needle and filename as a BOF.☆32Sep 27, 2021Updated 4 years ago
- ☆45Oct 16, 2023Updated 2 years ago
- Payload Generation Workflow☆41Jul 18, 2025Updated 9 months ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆189Mar 14, 2025Updated last year