Skip to content

Collection of beacon BOF written to learn windows and cobaltstrike

Notifications You must be signed in to change notification settings

rvrsh3ll/CobaltStrike-BOF

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 

Repository files navigation

CobaltStrike-BOF

Collection of beacon BOF written to learn windows and cobaltstrike

1 ) DCOM-Lateral-BOF.c

A quick PoC that uses DCOM (ShellWindows) for lateral movement. You will have to provide creds (username, password, and domain) on line 93-95 for it to work. If you wish to use the current user credentials, you can change line 110 to "authInfo->pAuthIdentityData = t2;", which is basically NULL. An aggressor script will follow. This is not meant to be used in production, it is just a PoC. A more useable version will land with the aggressor script.

To read more about porting (D)COM to C, please refer to this article: https://yaxser.github.io/CobaltStrike-BOF/

2 ) after the write up...

About

Collection of beacon BOF written to learn windows and cobaltstrike

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C 100.0%