kernel-mii

Kernel exploit

Exploits a kernel vulnerability to gain SYSTEM privileges on Windows.

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

GitHub

29 stars
1 watching
6 forks
Language: C
last commit: over 3 years ago

Related projects:

RepositoryDescriptionStars
boku7/halosgate-psA Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.95
octoberfest7/cve-2023-36874_bofAn exploit tool for a Windows vulnerability allowing an attacker to run arbitrary code as SYSTEM on Windows 10 and Windows 11202
riccardoancarani/bofsUtilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes112
0x3rhy/adduser-bofA Cobalt Strike BOF that exploits a vulnerability to add an admin user70
airbus-cert/invoke-bofLoads and executes a malicious payload in a Windows system using PowerShell.245
cobalt-strike/bof-vsA Beacon Object File Visual Studio template project for creating malicious code executables145
mlcsec/asrenum-bofTools to detect and exploit vulnerabilities in Windows Attack Surface Reduction (ASR) settings142
nvisosecurity/cobaltwhispersAn aggressor script that allows Cobalt Strike to perform process injection and persistence by leveraging direct syscalls to bypass EDR/AV systems.229
xairy/kernel-exploitsA collection of proof-of-concept exploits for vulnerabilities in the Linux kernel1,454
b1tg/cobaltstrike-beacon-rustA Cobalt Strike beacon implementation in Rust for creating malicious network connections180
huoji120/cobaltstrikedetectedDetects potential Cobalt Strike malware by analyzing memory allocation patterns during code execution272
ccob/bof.netA .NET runtime framework for developing and executing malicious C code in a managed environment.682
pwn1sher/cs-bofsA collection of compiled beacon object files from the CobaltStrike platform.101
boku7/spawnA Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection.440
rsmudge/cve-2020-0796-bofExploits a vulnerability in SMBv3 compression to achieve privilege escalation and process manipulation.68