endymi's repositories

Jicop-H00k

contains the core files required to create a Beacon Object File (BOF) for use with AM0N-Eye. BOFs are compiled C programs written in a specific convention that allows them to execute within a Beacon process and use internal Beacon APIs. BOFs provide a fast and efficient way to extend the Beacon

Stargazers:0Issues:0Issues:0

SharpShares

Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain

License:MITStargazers:0Issues:0Issues:0

Mockingjay_BOF

Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique

Stargazers:0Issues:0Issues:0

C2-Tool-Collection

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Stargazers:0Issues:0Issues:0
License:BSD-3-ClauseStargazers:0Issues:0Issues:0

DeepFaceLab

DeepFaceLab is the leading software for creating deepfakes.

License:GPL-3.0Stargazers:0Issues:0Issues:0

EnableWebDAVClient-BOF

Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts

License:GPL-3.0Stargazers:0Issues:0Issues:0

GATOR

GATOR - GCP Attack Toolkit for Offensive Research, a tool designed to aid in research and exploiting Google Cloud Environments

License:NOASSERTIONStargazers:0Issues:0Issues:0

badger-builder

badger-builder is an AI-assisted tool for generating dynamic Brute Ratel C4 profiles

Stargazers:0Issues:0Issues:0

ScreenshotBOF

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Stargazers:0Issues:0Issues:0

WdToggle

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.

Stargazers:0Issues:0Issues:0

PrivKit

PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.

License:GPL-3.0Stargazers:0Issues:0Issues:0

BOF-DCOMPotato-PrintNotify

Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object to DCOM call of PrintNotify.

Stargazers:0Issues:0Issues:0

non-ms-binaries

Code snippet to create a process using the "PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON" flag

Stargazers:0Issues:0Issues:0

whereami

Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.

License:MITStargazers:0Issues:0Issues:0

xPipe

Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions

License:MITStargazers:0Issues:0Issues:0

BOFs-snov

Beacon Object Files (not Buffer Overflows)

License:BSD-2-ClauseStargazers:0Issues:0Issues:0

ServiceSetSD-Bof

Beacon Object file set service sd

Stargazers:0Issues:0Issues:0

BOF-RemoteRegSave

Cobalt Strike Beacon Object File (BOF) that uses RegConnectRegistryA + RegOpenKeyExA API to dump registry hives on remote computer

Stargazers:0Issues:0Issues:0

BOF-SprayAD

Cobalt Strike Beacon Object File (BOF) that uses LogonUserSSPI API to perform kerberos-based password spray

Stargazers:0Issues:0Issues:0

samdump-bof

Beacon Object File Dump sam file

Stargazers:0Issues:0Issues:0

msspray

Password attacks and MFA validation against various endpoints in Azure and Office 365

License:MITStargazers:0Issues:0Issues:0

amd-ryzen-master-driver-v17-exploit

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

License:MITStargazers:0Issues:0Issues:0

ASRenum-BOF

Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations

Stargazers:0Issues:0Issues:0

bof-collection

Collection of Beacon Object Files (BOF) for Cobalt Strike

Stargazers:0Issues:0Issues:0

BOF-CredUI

Cobalt Strike Beacon Object File (BOF) that uses CredUIPromptForWindowsCredentials API to invoke credential prompt

Stargazers:0Issues:0Issues:0

LdapSignCheck

Beacon Object File & C# project to check LDAP signing

Stargazers:0Issues:0Issues:0

EXOCET-AV-Evasion

EXOCET - AV-evading, undetectable, payload delivery tool

Stargazers:0Issues:0Issues:0

BOFs-Ransomware-

Collection of personal Beacon Object Files (BOFs)

Stargazers:0Issues:0Issues:0

InlineWhispers2

Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2

License:GPL-3.0Stargazers:0Issues:0Issues:0