{"repo":"The-Z-Labs/bof-launcher","free":true,"listed":false,"github":"https://github.com/The-Z-Labs/bof-launcher","clone":"git clone https://github.com/The-Z-Labs/bof-launcher.git","description":"[ BOF-LAUNCHER ] -> an API for loading, executing and in-memory masking BOFs on Windows and Linux for use in C/Zig/Go/Rust agents/implants. [ Z-BEAC0N ] -> a custom-written stage-1 (aka pre-C2) solution engineered with a small footprint, stealth and modularity in mind. [ DEVELOPED BOFS ] -> cross-platform (12), Linux-only (10), Win-only (2)","language":"Zig","stars":336,"topics":["bof","beacon","beaconobjectfile","post-exploitation","cobalt-strike","in-memory","cybersecurity","security-tools","adversarial-attacks","red-team"],"license":null,"category":"security-tools","readme_excerpt":"Introduction Cobalt Strike 4.1 released on 25 June 2020, introduced a novel (for that time) capability of running so called Beacon Object Files - small post-ex capabilities that execute in Beacon, parse arguments, call a few Win32 APIs, report output, and exit . Since that time BOFs became very popular and the demand to launch/execute them in other environments than Cobalt Strike's Beacon has emerged. We at Z-Labs saw a big potential in BOFs and decided to extend its capabilities, versatility and usefulness even further. That's how the following projects came to live. The repository provides: 1. bof-launcher - programming library for BOFs in-memory management (loading, keeping track of loaded BOFs, execution, masking). 2. z-beac0n - a custom-written stage-1 (aka pre-C2) solution featuring bof-launcher. Engineered with a small footprint, stealth and modularity in mind. 3. Z-Labs BOFs collection - growing collection of OS-specific and cross-platform BOFs for usage during a red team engagements. See here for bulding instructions. bof-launcher library BOF launcher library is the engine behind the z-beac0n adversary simulation toolkit. It is a standalone programming library implemented in Zig and C that can be used to execute BOFs. On Windows it support x86 and x86 64 architectures, on Linux x86, x86 64, ARMv6+ and AArch64 architectures are supported. The library exposes either C API and Zig API. Library features: - Capable of running BOFs that adhere to Windows BOF template and L","default_branch":null,"files":null,"tree":[],"storefront":"/r/The-Z-Labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/The-Z-Labs/bof-launcher/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}