kernel-mii
Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.
AI summary
Kernel exploit
Exploits a kernel vulnerability to gain SYSTEM privileges on Windows.
- stars
- 29
- forks
- 6
- watching
- 1
Similar projects
Found by comparing what the projects do, not just their names.
System info BOF
A Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.
Windows privilege escalation exploit
An exploit tool for a Windows vulnerability allowing an attacker to run arbitrary code as SYSTEM on Windows 10 and Windows 11
Beacon utilities
Utilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes
BOF tool
A Cobalt Strike BOF that exploits a vulnerability to add an admin user
Payload loader
Loads and executes a malicious payload in a Windows system using PowerShell.
BOF executable generator
A Beacon Object File Visual Studio template project for creating malicious code executables
ASR scanner
Tools to detect and exploit vulnerabilities in Windows Attack Surface Reduction (ASR) settings
Intrusion tool
An aggressor script that allows Cobalt Strike to perform process injection and persistence by leveraging direct syscalls to bypass EDR/AV systems.
Linux kernel exploits
A collection of proof-of-concept exploits for vulnerabilities in the Linux kernel
Malicious connection maker
A Cobalt Strike beacon implementation in Rust for creating malicious network connections
Memory malware detector
Detects potential Cobalt Strike malware by analyzing memory allocation patterns during code execution
ccob/bof.net682
C runtime framework
A .NET runtime framework for developing and executing malicious C code in a managed environment.
Beacon libraries
A collection of compiled beacon object files from the CobaltStrike platform.
boku7/spawn440
Process spawner
A Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection.
SMBGhost Exploit
Exploits a vulnerability in SMBv3 compression to achieve privilege escalation and process manipulation.