som3canadian / Cloudflare-RedirectorView external linksLinks
Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.
☆184Mar 14, 2025Updated 11 months ago
Alternatives and similar repositories for Cloudflare-Redirector
Users that are interested in Cloudflare-Redirector are comparing it to the libraries listed below
Sorting:
- Porting of BOF InlineExecute-Assembly to load .NET assembly in process but with patchless AMSI and ETW bypass using hardware breakpoint.☆273Apr 17, 2023Updated 2 years ago
- Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning☆137Dec 7, 2025Updated 2 months ago
- Adversary Emulation Framework☆129Jul 1, 2025Updated 7 months ago
- Terms of Use Conditional Access M365 Evilginx Phishlet☆44Jun 23, 2025Updated 7 months ago
- Lateral Movement via the .NET Profiler☆100Nov 21, 2024Updated last year
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆123Jan 17, 2026Updated last month
- A C# port from Invoke-GhostTask☆119Jan 5, 2024Updated 2 years ago
- A beacon object file implementation of PoolParty Process Injection Technique.☆432Dec 21, 2023Updated 2 years ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆381Dec 13, 2024Updated last year
- BOF to decrypt Signal Desktop chat logs☆71Feb 20, 2025Updated 11 months ago
- A Mythic Agent written in PIC C.☆206Feb 4, 2025Updated last year
- Internal Monologue BOF☆79Dec 28, 2024Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆345Nov 19, 2024Updated last year
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆670Aug 15, 2025Updated 6 months ago
- SoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.☆260Feb 21, 2025Updated 11 months ago
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆158Nov 7, 2023Updated 2 years ago
- Lateral Movement Using DCOM and DLL Hijacking☆325Jun 18, 2023Updated 2 years ago
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆859Feb 3, 2024Updated 2 years ago
- ☆259Jan 21, 2024Updated 2 years ago
- Azure Post Exploitation Framework☆244Oct 27, 2025Updated 3 months ago
- ☆121Nov 21, 2024Updated last year
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆307Dec 9, 2023Updated 2 years ago
- Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy☆167Nov 17, 2025Updated 3 months ago
- An App Domain Manager Injection DLL PoC on steroids☆211Dec 14, 2023Updated 2 years ago
- ☆235Oct 8, 2024Updated last year
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework☆637May 8, 2025Updated 9 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆200Apr 21, 2025Updated 9 months ago
- Weaponizing DCOM for NTLM Authentication Coercions☆275Jul 1, 2025Updated 7 months ago
- .NET assembly loader with patchless AMSI and ETW bypass☆366Apr 19, 2023Updated 2 years ago
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆75Oct 27, 2025Updated 3 months ago
- "Service-less" driver loading☆184Nov 28, 2024Updated last year
- Parser and reconciliation tooling for large Active Directory environments.☆33Feb 18, 2025Updated 11 months ago
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer☆539Feb 13, 2024Updated 2 years ago
- ☆137Nov 17, 2025Updated 3 months ago
- early cascade injection PoC based on Outflanks blog post☆236Nov 7, 2024Updated last year
- ☆131Dec 4, 2023Updated 2 years ago
- A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and …☆332Mar 6, 2025Updated 11 months ago
- .NET Post-Exploitation Utility for Abusing Strong Explicit Certificate Mappings in ADCS☆150Feb 10, 2025Updated last year
- Analyse your malware to surgically obfuscate it☆517Dec 17, 2025Updated 2 months ago