Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
-
Updated
Feb 2, 2026 - C++
Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
COM Hijacking VOODOO
Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options
Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
Tool for working with Indirect System Calls in Cobalt Strike's Beacon Object Files (BOF) using SysWhispers3 for EDR evasion
Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
BOFs gift wrapped for Havoc
Repository to gather the BOF files I will be developing
An experimental COFF loader for executing Cobalt Strike Beacon Object Files (BOFs)
🛡 Enumerate AV, EPP, EDR, and telemetry on Windows hosts using low-noise Cobalt Strike commands for tailored risk-based assessment.
🥶 Freeze EDR/AV processes with ColdWer, using WerFaultSecure.exe PPL bypass to extract LSASS memory on modern Windows systems.
Add a description, image, and links to the beacon-object-file topic page so that developers can more easily learn about it.
To associate your repository with the beacon-object-file topic, visit your repo's landing page and select "manage topics."