RDPHijack-BOF

Session hijacker

A tool for hijacking remote RDP sessions using the WinStationConnect API

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.

GitHub

297 stars
10 watching
45 forks
Language: C
last commit: about 4 years ago

Related projects:

RepositoryDescriptionStars
netero1010/servicemove-bofA tool that exploits a Windows vulnerability to execute arbitrary code on remote systems using a technique called DLL hijacking.284
octoberfest7/dropspawn_bofA CobaltStrike payload that uses DLL hijacking to spawn additional Beacons on Windows systems219
0x3rhy/adduser-bofA Cobalt Strike BOF that exploits a vulnerability to add an admin user70
airbus-cert/invoke-bofLoads and executes a malicious payload in a Windows system using PowerShell.245
cobalt-strike/unhook-bofRemoves API hooks from a malicious process54
boku7/halosgate-psA Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.95
cobalt-strike/bof-vsA Beacon Object File Visual Studio template project for creating malicious code executables145
rvrsh3ll/bof_collectionA collection of Cobalt Strike Beacon Objectives (BOFs) that perform various tasks such as domain information retrieval, clipboard data extraction, WiFi enumeration, port scanning, and registry persistence.593
redsection/offensivephA tool that utilizes an old driver to bypass user-mode access controls and inject malicious code into processes329
ccob/bof.netA .NET runtime framework for developing and executing malicious C code in a managed environment.682
crypt0p3g/bof-collectionA collection of beacon object files designed to be used in a remote access tool like Cobalt Strike.170
riccardoancarani/bofsUtilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes112
netero1010/quser-bofA proof-of-concept implementation of a Windows API-based backdoor using the quser.exe utility83
rsmudge/zerologon-bofAn implementation of a Zero Logon protocol Bounce Of Flood (ZoBoF) vulnerability exploitation technique157
tomcarver16/bof-dll-injectA tool for injecting malware into processes by mapping it to memory without registering it with the kernel.147