FindObjects-BOF

Process enumerator

An exploit tool that uses direct system calls to enumerate processes based on specific loaded modules or process handles

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

GitHub

266 stars
17 watching
47 forks
last commit: over 3 years ago

Related projects:

RepositoryDescriptionStars
outflanknl/inlinewhispersTool to generate inline assembly code for direct system calls in COBalt Strike's Beacon Object Files (BOF)308
outflanknl/recon-adAn Active Directory reconnaissance tool that uses ADSI and reflective DLLs to enumerate domain information and query user, group, and computer objects.316
outflanknl/c2-tool-collectionTools for exploiting vulnerabilities in Windows systems and gathering information about networked computers.1,155
boku7/whereamiA tool that extracts environment variables from a process without touching system DLLs using hand-crafted shellcode160
boku7/spawnA Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection.440
boku7/hollowA tool that enables remote process shellcode execution using the Early Bird injection technique267
outflanknl/wdtoggleA tool to enable WDigest credential caching using direct system calls in Cobalt Strike213
espressocake/ppldump_bofA tool for dumping the memory contents of a protected process on Windows136
boku7/halosgate-psA Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.95
espressocake/dll-hijack-search-order-bofA tool to enumerate the search order of DLL resolution and potentially gain information about a file's mutability.141
outflanknl/helpcolorLists available Cobalt Strike beacon commands and colors them based on their type191
cobalt-strike/unhook-bofRemoves API hooks from a malicious process54
iilegacyyii/threadlessinject-bofA tool that enables process injection without thread creation by hooking an export function from a remote process.369
crypt0p3g/bof-collectionA collection of beacon object files designed to be used in a remote access tool like Cobalt Strike.170
mainframed/enumerationA collection of scripts and tools to help enumerate and interact with z/OS systems63