Atomic test units for BOF execution
☆60Apr 26, 2026Updated 3 months ago
Alternatives and similar repositories for atomic-bofs
Users that are interested in atomic-bofs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated 3 weeks ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆118Aug 4, 2026Updated last week
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Jul 23, 2026Updated 3 weeks ago
- A Crystal Palace shared library to resolve & perform syscalls☆66Oct 29, 2025Updated 9 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆58Jul 4, 2026Updated last month
- abusing windows toast notifications for fun and user manipulation☆106Jul 11, 2026Updated last month
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 9 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 3 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 3 months ago
- dcsync bof☆54Feb 13, 2026Updated 6 months ago
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated 2 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆92Feb 6, 2026Updated 6 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Open Source Implementation of Cobalt Strike's Malleable C2☆106Jun 27, 2026Updated last month
- A cmake template for crystal palace☆44Dec 20, 2025Updated 7 months ago
- Dockerized nginx app used to create high-level timeline visuals for red team assessments☆32Feb 25, 2026Updated 5 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆277Apr 16, 2026Updated 3 months ago
- Reimplementing Havoc Pro Runtime Channel Switching and Cobalt Strike UDC2 features.☆50Updated this week
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆138Jan 21, 2026Updated 6 months ago
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆37Jan 17, 2026Updated 6 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆116Apr 16, 2026Updated 3 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆146Apr 22, 2026Updated 3 months ago
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆134Apr 6, 2026Updated 4 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated 2 weeks ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆69Jan 5, 2026Updated 7 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Aug 6, 2026Updated last week
- BOF for extracting Edge credentials from the main browser process.☆50May 5, 2026Updated 3 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Jul 23, 2026Updated 3 weeks ago
- Beacon Object File (BOF) for Using the BadSuccessor Technique for Account Takeover☆91Oct 20, 2025Updated 9 months ago
- A rust proof of concept to demonstrate registry overwriting via RegRestoreKey using the Offline Registry Library☆24Nov 13, 2025Updated 9 months ago
- Evasion kit for Cobalt Strike☆31Jan 16, 2026Updated 6 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆118Jan 26, 2026Updated 6 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago