Bobby Cooke

Results 18 repositories owned by Bobby Cooke

AsmHalosGate

128
Stars
22
Forks
Watchers

x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks

azureOutlookC2

317
Stars
72
Forks
Watchers

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Micro...

BokuLoader

1.2k
Stars
244
Forks
Watchers

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

halosgate-ps

50
Stars
19
Forks
Watchers

Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes

HellsGatePPID

90
Stars
21
Forks
Watchers

Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process

HOLLOW

201
Stars
50
Forks
Watchers

EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode

injectAmsiBypass

306
Stars
60
Forks
Watchers

Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.

injectEtwBypass

238
Stars
50
Forks
Watchers

CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)

Ninja_UUID_Runner

356
Stars
78
Forks
Watchers

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

Nobelium-PdfDLRunAesShellcode

94
Stars
26
Forks
Watchers

A recreation of the "Nobelium" malware based on Microsofts Malware analysis - Part 1: PDF2Pwn