BOF
A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.
Grab unsaved Notepad contents with a Beacon Object File
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.
POC tool to convert CobaltStrike BOF files to raw shellcode
An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.
WindowSpy is a Cobalt Strike Beacon Object File meant for automated and targeted user surveillance.
Situational Awareness commands implemented using Beacon Object Files
A BOF to determine Windows Defender exclusions.
BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.
CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
Take a screenshot without injection for Cobalt Strike
Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes
C or BOF file to extract WebKit master key to decrypt user cookie
Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE
BOF to steal browser cookies & credentials