RDPHijack-BOF
by netero1010
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.
AI summary
Session hijacker
A tool for hijacking remote RDP sessions using the WinStationConnect API
- stars
- 297
- forks
- 45
- watching
- 10
Similar projects
Found by comparing what the projects do, not just their names.
DLL Hijacker
A tool that exploits a Windows vulnerability to execute arbitrary code on remote systems using a technique called DLL hijacking.
DLL hijacker
A CobaltStrike payload that uses DLL hijacking to spawn additional Beacons on Windows systems
BOF tool
A Cobalt Strike BOF that exploits a vulnerability to add an admin user
Payload loader
Loads and executes a malicious payload in a Windows system using PowerShell.
Process hook remover
Removes API hooks from a malicious process
System info BOF
A Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.
BOF executable generator
A Beacon Object File Visual Studio template project for creating malicious code executables
Cobalt Strike BOFs
A collection of Cobalt Strike Beacon Objectives (BOFs) that perform various tasks such as domain information retrieval, clipboard data extraction, WiFi enumeration, port scanning, and registry persistence.
Process hijacker
A tool that utilizes an old driver to bypass user-mode access controls and inject malicious code into processes
ccob/bof.net682
C runtime framework
A .NET runtime framework for developing and executing malicious C code in a managed environment.
Beacon objects
A collection of beacon object files designed to be used in a remote access tool like Cobalt Strike.
Beacon utilities
Utilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes
Backdoor
A proof-of-concept implementation of a Windows API-based backdoor using the quser.exe utility
Vulnerability exploiter
An implementation of a Zero Logon protocol Bounce Of Flood (ZoBoF) vulnerability exploitation technique
Memory injector
A tool for injecting malware into processes by mapping it to memory without registering it with the kernel.