
CVE-2024-26229-BOF
BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

In-memory token vault BOF for Cobalt Strike

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)