mlcsec / EDRenum-BOF
Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.
☆121Updated 7 months ago
Alternatives and similar repositories for EDRenum-BOF:
Users that are interested in EDRenum-BOF are comparing it to the libraries listed below
- ☆106Updated 2 months ago
- Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options☆136Updated last month
- .NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCS☆143Updated 2 months ago
- The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning☆112Updated last month
- ☆97Updated 8 months ago
- Adversary Emulation Framework☆98Updated 9 months ago
- A Mythic agent for Windows written in C☆120Updated last week
- ☆126Updated 8 months ago
- ☆87Updated 11 months ago
- Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning☆129Updated last week
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆152Updated last year
- Library of BOFs to interact with SQL servers☆163Updated 3 weeks ago
- ☆109Updated 3 months ago
- A C# port from Invoke-GhostTask☆114Updated last year
- Lateral Movement☆123Updated last year
- Port of Cobalt Strike's Process Inject Kit☆173Updated 5 months ago
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆179Updated 2 months ago
- Tool for working with Indirect System Calls in Cobalt Strike's Beacon Object Files (BOF) using SysWhispers3 for EDR evasion☆80Updated 3 weeks ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆88Updated last week
- ApexLdr is a DLL Payload Loader written in C☆108Updated 9 months ago
- 🧠 The ultimate, community-curated resource for Beacon Object Files (BOFs) — tutorials, how-tos, deep dives, and reference materials.☆65Updated last week
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆151Updated 2 weeks ago
- Ghosting-AMSI☆136Updated last week
- ☆54Updated 2 months ago
- ☆179Updated last month
- Modified versions of the Cobalt Strike Process Injection Kit☆94Updated last year
- ☆105Updated last month
- Execute commands in other Sessions☆86Updated 9 months ago
- AzureAD beacon object files☆118Updated 4 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated last year