
CVE-2026-49176_BOF
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)

CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…


BOF to run PE in Cobalt Strike Beacon without console creation

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

Cobalt Strike Beacon Object File for automated, targeted user surveillance. Triggers screenshots or custom actions when specific window titles (e.g.,…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

CVE-2024-35250 的 Beacon Object File (BOF) 实现。

Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…