Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse LSASS dump files and registry hive files to extract credentials and other secrets stored without downloading the file and without uploading any suspicious code to the beacon.
☆154Apr 27, 2021Updated 5 years ago
Alternatives and similar repositories for aggrokatz
Users that are interested in aggrokatz are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.☆141Sep 24, 2021Updated 5 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆245Jul 14, 2021Updated 5 years ago
- Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.☆290Jun 8, 2026Updated 4 months ago
- A BOF.NET program to split a file into smaller chunks and email it via a specified SMTP relay.☆17Jun 24, 2021Updated 5 years ago
- ☆100Aug 23, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆464Mar 8, 2023Updated 3 years ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆105Jan 7, 2022Updated 4 years ago
- Agressor script that lists available Cobalt Strike beacon commands and colors them based on their type☆216Mar 18, 2024Updated 2 years ago
- A beacon generator using Cobalt Strike and a variety of tools.☆446Aug 10, 2021Updated 5 years ago
- Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2☆186Jul 21, 2022Updated 4 years ago
- DLL Hijack Search Order Enumeration BOF☆147Nov 3, 2021Updated 4 years ago
- Remove API hooks from a Beacon process.☆282Sep 18, 2021Updated 5 years ago
- Cobalt Strike BOF for quser.exe implementation using Windows API☆89Mar 22, 2023Updated 3 years ago
- This aggressor script uses a beacon's note field to indicate the health status of a beacon.☆143Sep 29, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Project to enumerate proxy configurations and generate shellcode from CobaltStrike☆138Nov 4, 2020Updated 5 years ago
- (kinda) Malicious Outlook Reader☆137Mar 3, 2021Updated 5 years ago
- Vampire is an aggressor script which integrates with BloodHound to mark nodes as owned.☆78Apr 6, 2021Updated 5 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆219Jul 14, 2021Updated 5 years ago
- Cobalt Strike Beacon Object Files☆167May 2, 2022Updated 4 years ago
- AutoStart teamserver and listeners with services☆73Dec 23, 2021Updated 4 years ago
- An interactive command prompt for red teaming and pentesting. Automatically pushes commands through SOCKS4/5 proxies via proxychains. Opt…☆227Aug 23, 2022Updated 4 years ago
- Collection of beacon BOF written to learn windows and cobaltstrike☆360Feb 24, 2023Updated 3 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆787Sep 4, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆120Jun 17, 2022Updated 4 years ago
- Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.☆379Mar 8, 2023Updated 3 years ago
- EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and e…☆290Mar 8, 2023Updated 3 years ago
- C# .Net 5.0 project to build BOF (Beacon Object Files) in mass☆24Oct 2, 2026Updated last week
- A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certifica…☆876Mar 20, 2023Updated 3 years ago
- ☆93May 14, 2022Updated 4 years ago
- Self-developed tools for Lateral Movement/Code Execution☆721Aug 17, 2021Updated 5 years ago
- Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes☆107Mar 8, 2023Updated 3 years ago
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆273May 3, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.☆217May 3, 2023Updated 3 years ago
- New UAC bypass for Silent Cleanup for CobaltStrike☆187Jul 14, 2021Updated 5 years ago
- Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)☆461Jul 15, 2022Updated 4 years ago
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.☆1,225Sep 29, 2026Updated last week
- A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.☆296Aug 18, 2023Updated 3 years ago
- ☆100Sep 20, 2021Updated 5 years ago
- My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+☆1,107Apr 19, 2023Updated 3 years ago