nick-frischkorn / TymSpecial
☆140Updated this week
Related projects: ⓘ
- Remove API hooks from a Beacon process.☆263Updated 3 years ago
- You shall pass☆241Updated 2 years ago
- A little tool to play with the Seclogon service☆301Updated 2 years ago
- A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.☆212Updated last year
- A BOF to automate common persistence tasks for red teamers☆263Updated last year
- CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process inject…☆225Updated last year
- A basic emulation of an "RPC Backdoor"☆207Updated 2 years ago
- ☆221Updated this week
- Useful Cobalt Strike BOFs found or used during engagements☆129Updated 11 months ago
- Move CS beacon to GPU memory when sleeping☆212Updated 2 years ago
- Pass the Hash to a named pipe for token Impersonation☆291Updated 9 months ago
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆291Updated last year
- Beacon Object File (BOF) Creation Helper☆219Updated 2 years ago
- Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File☆184Updated 3 years ago
- A Visual Studio template used to create Cobalt Strike BOFs☆278Updated 2 years ago
- Example code for using named pipe output with beacon ReflectiveDLLs☆108Updated 4 years ago
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆265Updated last year
- Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in…☆258Updated 3 years ago
- COFF file (BOF) for managing Kerberos tickets.☆276Updated last year
- ☆150Updated this week
- A Beacon Object File (BOF) is a compiled C program, written to a convention that allows it to execute within a Beacon process and use int…☆111Updated 2 months ago
- Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL…☆160Updated last year
- BOF combination of KillDefender and Backstab☆153Updated last year
- Collection of beacon BOF written to learn windows and cobaltstrike☆340Updated last year
- Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind☆414Updated last year
- Dumping LSASS with a duplicated handle from custom LSA plugin☆194Updated 2 years ago
- Reuse open handles to dynamically dump LSASS.☆231Updated 5 months ago
- ☆245Updated this week
- CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)☆274Updated 2 years ago