
Aggressor-Aggregator
A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.
CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

In-memory token vault BOF for Cobalt Strike

A BOF that runs unmanaged PEs inline

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Cobalt Strike aggressor script for generating, formatting, and encrypting beacon shellcode with support for multiple exit methods, syscalls, and…

Remove API hooks from a Beacon process.

Practice Go programming and implement CobaltStrike's Beacon in Go

C2 tool routing Cobalt Strike beacon data over LDAP user attributes for stealthy command-and-control in segmented networks.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Cobalt Strike HTTPS beaconing over Microsoft Graph API

This aggressor script uses a beacon's note field to indicate the health status of a beacon.