Bobby Cooke

Results 26 repositories owned by Bobby Cooke

AsmHalosGate

229
Stars
31
Forks
229
Watchers

x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks

azureOutlookC2

499
Stars
99
Forks
499
Watchers

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Micro...

BokuLoader

1.4k
Stars
268
Forks
1.4k
Watchers

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

halosgate-ps

110
Stars
20
Forks
110
Watchers

Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes

HellsGatePPID

106
Stars
22
Forks
106
Watchers

Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process

HOLLOW

291
Stars
62
Forks
291
Watchers

EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode

injectAmsiBypass

383
Stars
70
Forks
383
Watchers

Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.

injectEtwBypass

300
Stars
56
Forks
300
Watchers

CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)

Ninja_UUID_Runner

450
Stars
87
Forks
450
Watchers

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

Nobelium-PdfDLRunAesShellcode

102
Stars
25
Forks
102
Watchers

A recreation of the "Nobelium" malware based on Microsofts Malware analysis - Part 1: PDF2Pwn