Invoke-Bof

Payload loader

Loads and executes a malicious payload in a Windows system using PowerShell.

Load any Beacon Object File using Powershell!

GitHub

245 stars
11 watching
34 forks
Language: PowerShell
last commit: almost 5 years ago
cobalt-strikepowershell

Related projects:

RepositoryDescriptionStars
cobalt-strike/bof-vsA Beacon Object File Visual Studio template project for creating malicious code executables145
guervild/bofsBeacon object files for Cobalt Strike158
offsecginger/aes-powershellcodeA PowerShell payload designed to evade detection and execute malicious commands on a target system108
boku7/halosgate-psA Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.95
boku7/spawnA Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection.440
riccardoancarani/bofsUtilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes112
octoberfest7/dropspawn_bofA CobaltStrike payload that uses DLL hijacking to spawn additional Beacons on Windows systems219
xx0hcd/alt-beacon-payloadCreates a custom C# beacon payload with AV bypass and shellcode injection capabilities20
cobalt-strike/unhook-bofRemoves API hooks from a malicious process54
crypt0p3g/bof-collectionA collection of beacon object files designed to be used in a remote access tool like Cobalt Strike.170
northwavesecurity/kernel-miiExploits a kernel vulnerability to gain SYSTEM privileges on Windows.29
0x3rhy/adduser-bofA Cobalt Strike BOF that exploits a vulnerability to add an admin user70
netero1010/trustedpath-uacbypass-bofTools and techniques to bypass Windows UAC restrictions on executable files by utilizing DCOM objects119
boku7/injectetwbypassTool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall276
boku7/injectamsibypassA tool that bypasses AMSI in a remote process with code injection.377