Skip to content
View coldfusion39's full-sized avatar
Block or Report

Block or report coldfusion39

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Cobalt Strike

142 repositories

Cobalt Strike UDRL for memory scanner evasion.

C 839 157 Updated Jun 4, 2024

A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process

C 86 16 Updated Aug 29, 2022

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

C 544 63 Updated Sep 26, 2023

Sleep Obfuscation

C 36 3 Updated Oct 13, 2022

COFF file (BOF) for managing Kerberos tickets.

C 275 31 Updated Jul 2, 2023

A BOF to determine Windows Defender exclusions.

C++ 231 36 Updated Jun 25, 2023

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

C 129 25 Updated Jan 21, 2023

Execute unmanaged Windows executables in CobaltStrike Beacons

C 602 93 Updated Mar 4, 2023

A PoC implementation for dynamically masking call stacks with timers.

C++ 239 33 Updated Feb 13, 2023

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

C 387 56 Updated Apr 8, 2024

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 359 50 Updated Jan 9, 2024

Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature

C 93 8 Updated Feb 28, 2023

Improved version of EKKO by @5pider that Encrypts only Image Sections

C++ 105 24 Updated Feb 13, 2023

Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process

C 38 9 Updated Mar 15, 2023

A proof of concept I developed to improve Gargoyle back in 2018 to achieve true memory obfuscation from position independent code

C 33 15 Updated Mar 20, 2023

A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge years ago.

C 145 50 Updated Mar 20, 2023

A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.

C 53 8 Updated May 2, 2023

old postex for grabbing a krbtgs for my current user

C 28 8 Updated Jun 8, 2023

HVNC for Cobalt Strike

C 1,128 179 Updated Dec 7, 2023

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

C 214 26 Updated Jun 8, 2023
C 116 14 Updated Jun 28, 2023

Example of using Sleep to create better named pipes.

41 3 Updated Jul 25, 2023