
AceLdr
Cobalt Strike UDRL for memory scanner evasion.

Cobalt Strike UDRL for memory scanner evasion.

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Various Cobalt Strike BOFs

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon

C# tool to retrieve LAPS passwords from Active Directory via LDAP, designed for in-memory execution within Cobalt Strike sessions using…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Cobalt Strike BOF for live Windows enumeration of open file handles, revealing which process has locked a target file on disk during…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Cobalt Strike BOF that retrieves Windows geolocation coordinates via WinRT and legacy ILocation APIs, with automatic registry permission management.

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

D(COM) V(ulnerability) S(canner) AKA Devious swiss army knife - Lateral movement using DCOM Objects