-
zip_smuggling Public
Python3 utility for creating zip files that smuggle additional data for later extraction
-
Stardust Public
Forked from Cracked5pider/StardustA modern 32/64-bit position independent implant template
C UpdatedMar 21, 2025 -
Secure_Stager Public
An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution
-
Enumprotections_BOF Public
A BOF to enumerate system process, their protection levels, and more.
-
-
MemFiles Public
A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk
-
TeamsPhisher Public
Send phishing messages and attachments to Microsoft Teams users
-
-
Shoggoth Public
Forked from frkngksl/ShoggothShoggoth: Asmjit Based Polymorphic Encryptor
-
CVE-2023-36874_BOF Public
Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE
-
DropSpawn_BOF Public
CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
-
aggressor_snippets Public
A collection of random small Aggressor snippets that don't warrant their own repo
-
KDStab Public
BOF combination of KillDefender and Backstab
-
Inline-Execute-PE Public
Execute unmanaged Windows executables in CobaltStrike Beacons
-
Cohab_Processes Public
A small Aggressor script to help Red Teams identify foreign processes on a host machine
-
lnk_generator Public
Small project to facilitate creation of .lnk payloads
-
Presentations Public
Slide decks and/or materials from conference presentations
-
CS_Uploads_Tracker Public
Aggressor script add-in for CobaltStrike to track file uploads
-
Proxy_Egress_Persistence Public
A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies
-
KillDefender_BOF Public
Beacon Object File implementation of pwn1sher's KillDefender
-
KillDefender Public
Forked from pwn1sher/KillDefenderA small (Edited) POC to make defender useless by removing its token privileges and lowering the token integrity
-
BeatRev Public
POC for frustrating/defeating Malware Analysts
-
DNS_Tunneling Public
DNS Tunneling using powershell to download and execute a payload. Works in CLM.
-
-
JumpSession_BOF Public
Beacon Object File allowing creation of Beacons in different sessions.
-
EventViewerUAC_BOF Public
Beacon Object File implementation of Event Viewer deserialization UAC bypass
-
Writeup of Payload Techniques in C involving Mutants, Session 1 -> Session 0 migration, and Self-Deletion of payloads.
-
-
Backstab_BOF Public
Beacon Object File implementation of Yaxser's Backstab