endymi's repositories

bofs-check-creds

Miscellaneous Cobalt Strike Beacon Object Files

License:GPL-3.0Stargazers:0Issues:0Issues:0

KillDefender

A small POC to make defender useless by removing its token privileges and lowering the token integrity

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

NoteThief

Grab unsaved Notepad contents with a Beacon Object File

Stargazers:0Issues:0Issues:0

TokenStripBOF

Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process

Stargazers:0Issues:0Issues:0

BOF-CobaltStrike

Useful Cobalt Strike Beacon Object Files (BOFs) used during red teaming and penetration testing engagements.

Stargazers:0Issues:0Issues:0

SharpAllTheThings

The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.

Stargazers:0Issues:0Issues:0

JumpSession_BOF

Beacon Object File allowing creation of Beacons in different sessions.

License:MITStargazers:0Issues:0Issues:0

EventViewerUAC_BOF

Beacon Object File implementation of Event Viewer deserialization UAC bypass

License:MITStargazers:0Issues:0Issues:0

BOFs

Cobalt Strike Beacon Object Files

Stargazers:1Issues:0Issues:0

KillDefenderBOF

Beacon Object File PoC implementation of KillDefender

Stargazers:0Issues:0Issues:0

Backstab_BOF

Beacon Object File implementation of Yaxser's Backstab

Stargazers:0Issues:0Issues:0

BofRoast

Beacon Object Files for roasting Active Directory

Stargazers:0Issues:0Issues:0

sandbox-process-bof

A Beacon Object File (BOF) to sandbox a process

Stargazers:0Issues:0Issues:0

BOF_dumpclip

Beacon Object Files to dump content of clipboard

Stargazers:0Issues:0Issues:0

tgtdelegation

tgtdelegation is a Beacon Object File (BOF) to obtain a usable TGT via the "TGT delegation trick"

Stargazers:0Issues:0Issues:0

DLL_Version_Enumeration_BOF

A BOF for enumerating version information for DLLs associated for a Beacon process.

Stargazers:0Issues:0Issues:0

Firewall_Walker_BOF

A BOF to interact with COM objects associated with the Windows software firewall.

Stargazers:0Issues:0Issues:0

GetWebDAVStatus

Determine if the WebClient Service (WebDAV) is running on a remote system

Stargazers:0Issues:0Issues:0

PPLDump_BOF

A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

BOFs-Ricardo

Collection of Beacon Object Files (BOFs) for shells and lols

Stargazers:1Issues:0Issues:0
Stargazers:0Issues:0Issues:0

TrustedPath-UACBypass-BOF

Cobalt Strike beacon object file implementation for trusted path UAC bypass. The target executable will be called without involving "cmd.exe" by using DCOM object.

Stargazers:0Issues:0Issues:0

Detect-Hooks

Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

CVE-2021-30481

https://nvd.nist.gov/vuln/detail/CVE-2021-30481

Stargazers:0Issues:0Issues:0

Eventlogedit-evtx--Evolution

Remove individual lines from Windows XML Event Log (EVTX) files

Stargazers:0Issues:0Issues:0

BOF-RegSave

Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File

Stargazers:0Issues:0Issues:0

BOF-DLL-Inject

Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files.

Stargazers:0Issues:0Issues:0