-
ScreenshotBOF Public
Forked from CodeXTF2/ScreenshotBOFAn alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.
C MIT License UpdatedDec 7, 2025 -
Beacon Object File (BOF) for identifying dependent child services of a given parent.
-
bloodhound_community Public
Configuration generator and metadata grabber for containerized Bloodhound Community Edition deployments
-
adidns_walker Public
Parse records of ADIDNS dumped data for valid A records with associated IP addresses
-
ADIDNS_Parser Public
Parser and reconciliation tooling for large Active Directory environments.
-
A VSCode plugin to assist with BOF development.
-
Toggle_Token_Privileges_BOF Public
Syscall BOF to arbitrarily add/detract process token privilege rights.
-
DojoLoader Public
Forked from naksyn/DojoLoaderGeneric PE loader for fast prototyping evasion techniques
-
-
-
Bloodhound_Community_Docker Public
Generator of docker-compose file to allow secure configurations and multi-deployment strategy.
-
DefenderPathExclusions Public
Creation and removal of Defender path exclusions and exceptions in C#.
-
-
ligolo-ng Public
Forked from nicocha30/ligolo-ngAn advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
-
BetterPipename Public
Example of using Sleep to create better named pipes.
-
BOF_Development_Docker Public
A VSCode devcontainer for development of COFF files with batteries included.
-
Defender_Exclusions-BOF Public
A BOF to determine Windows Defender exclusions.
-
-
BOF.NET Public
Forked from williamknows/BOF.NETA .NET Runtime for Cobalt Strike's Beacon Object Files
C UpdatedMay 22, 2023 -
dufflebag Public
Forked from BishopFox/dufflebagSearch exposed EBS volumes for secrets
Go GNU General Public License v3.0 UpdatedApr 24, 2023 -
REFramework Public
Forked from praydog/REFrameworkScripting platform, modding framework and VR support for all RE Engine games
C++ MIT License UpdatedApr 1, 2023 -
proxyplease Public
Forked from aus/proxypleaseCross-platform proxy selection with optional native authentication negotiation
Go MIT License UpdatedFeb 25, 2023 -
MITRE_ATTACK_CLI Public
CLI Search for Security Operators of MITRE ATT&CK URLs
-
RecreateCSDownloadsTree Public
Generation of TOML metadata for recreating directory structures from Cobalt Strike Beacon downloads.
-
-
callback_injection-Csharp Public
Forked from 0xsp-SRD/callback_injection-Csharpthis repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback functions
C# MIT License UpdatedJun 24, 2022 -
TitanLdr Public
Forked from moonlight-junky/TitanLdrPublic variation of Titan Loader
-
DynamicTabRename Public
CNA that interacts with a JAR file to dynamically rename GUI tabs within Cobalt Strike from a JSON file.
-
-
