hittimes / BOFs

Collection of beacon object files for use with Cobalt Strike to facilitate 🐚.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Beacon Object Files

Name Syntax
MiniDumpWriteDump minidumpwritedump <PID> <path_of_dmp?>

MiniDumpWriteDump BOF (64-bit only)

Custom implementation of DbgHelp's MiniDumpWriteDump function. Uses static syscalls to replace low-level functions like NtReadVirtualMemory.

Syscalls generated using @jthuraisamy's SysWhispers and @Outflanknl's InlineWhispers.

Code is adapted from ReactOS's implementation of MiniDumpWriteDump at minidump.c.

About

Collection of beacon object files for use with Cobalt Strike to facilitate 🐚.


Languages

Language:C 97.0%Language:C++ 2.7%Language:Makefile 0.2%