
New releaseAug 16, 2026
Adrenaline execution-wevt_logon_enum-2026-08-15-193403-18b9393
C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.
Adrenaline BOF Kit
A C2-agnostic collection of Beacon Object Files (BOFs) for red team and offensive security operations. BOFs are organized by attack chain phase and designed to be small, modular, and automation-friendly for use in reconnaissance, enumeration, and post-exploitation workflows.
Table of Contents (MITRE taxonomy)
Collection
| BOF | Use |
|---|---|
| ai_surface | Maps AI tooling on Windows developer endpoints and highlights their configuration artifacts that may expose server definitions, commands, arguments, and embedded credentials. |
| clipboard_grab | Retrieves text data from the Windows clipboard using Win32 APIs and returns the contents to the callback. Original Code Credits: @rvrsh3ll |
| ide_extension_surface | Enumerates VS Code, Cursor, Windsurf, Zed, Insiders, OSS, and server/remote extension manifests from per-user profile roots and summarizes extension identity, activation events, and capability signals. |
| powershell_history | Collects PowerShell history artifacts from default PSReadLine and transcript locations. Useful for locating credentials or infrastructure. |
| window_handles_enum | Enumerates window handles across all system processes and uses a legitimate window handle to access the clipboard. |
Community
| BOF | Use |
|---|---|
| notepad_grab | Extracts and returns plain text directly from open Notepad windows by reading memory, allowing operators to recover unsaved or in-memory notes. Useful for data collection from live endpoints. Original Source: NoteThief |
| schtask_enum | Enumerates scheduled tasks on Windows systems using the Task Scheduler COM interface. Provides a summary of tasks including their state, schedule, and configuration without overwhelming the beacon with XML data. Original Source: TrustedSec CS-Situational-Awareness-BOF |
| net_use | Add, list, or remove mapped drives via MPR (Modernized to manage memory properly, avoiding crashing) Original Source: TrustedSec CS-Situational-Awareness-BOF |
| session_view | Enumerates Windows Terminal Services sessions, displaying session IDs, usernames, domains, connection states, and session LUIDs. Original Source: SessionView by lsecqt |
Credential Access
| BOF | Use |
|---|---|
| certstore_loot | Enumerates local certificate stores to find certificates with exportable private keys and provides you with the path to export them. |
| cicd_credential_hunt | Finds common CI/CD, cloud, and developer credential artifacts in the current Windows user profile (GitHub/GitLab CLI, AWS/GCP, kube/Terraform, package managers, Git, SSH). Reports path and size by default; optional -verbose for bounded content previews. .gitconfig and .ssh/config are classified as configuration, not credential artifacts. |
| cloud_metadata_check | Probes cloud-local metadata services for AWS, Azure, and GCP from the current process, reporting provider identity, instance context, and bounded credential snippets when reachable. |
| process_tokens_list | Enumerates accessible tokens from running processes, showing user context, token type (primary/impersonation), and impersonation level. Supports optional filtering by PID or process name. SeDebugPrivilege is disabled by default for OPSEC. |