Pinned Repositories
CVE-2023-36874_BOF
Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE
DNS_Tunneling
DNS Tunneling using powershell to download and execute a payload. Works in CLM.
DropSpawn_BOF
CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
Inline-Execute-PE
Execute unmanaged Windows executables in CobaltStrike Beacons
KDStab
BOF combination of KillDefender and Backstab
MemFiles
A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk
OSEP-Tools
Secure_Stager
An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution
TeamsPhisher
Send phishing messages and attachments to Microsoft Teams users
XLL_Phishing
XLL Phishing Tradecraft
Octoberfest7's Repositories
Octoberfest7/TeamsPhisher
Send phishing messages and attachments to Microsoft Teams users
Octoberfest7/Inline-Execute-PE
Execute unmanaged Windows executables in CobaltStrike Beacons
Octoberfest7/MemFiles
A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk
Octoberfest7/XLL_Phishing
XLL Phishing Tradecraft
Octoberfest7/OSEP-Tools
Octoberfest7/DropSpawn_BOF
CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
Octoberfest7/DNS_Tunneling
DNS Tunneling using powershell to download and execute a payload. Works in CLM.
Octoberfest7/CVE-2023-36874_BOF
Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE
Octoberfest7/Secure_Stager
An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution
Octoberfest7/KDStab
BOF combination of KillDefender and Backstab
Octoberfest7/BeatRev
POC for frustrating/defeating Malware Analysts
Octoberfest7/EventViewerUAC_BOF
Beacon Object File implementation of Event Viewer deserialization UAC bypass
Octoberfest7/enumhandles_BOF
Octoberfest7/Mutants_Sessions_Self-Deletion
Writeup of Payload Techniques in C involving Mutants, Session 1 -> Session 0 migration, and Self-Deletion of payloads.
Octoberfest7/Enumprotections_BOF
A BOF to enumerate system process, their protection levels, and more.
Octoberfest7/Cohab_Processes
A small Aggressor script to help Red Teams identify foreign processes on a host machine
Octoberfest7/JumpSession_BOF
Beacon Object File allowing creation of Beacons in different sessions.
Octoberfest7/KillDefender_BOF
Beacon Object File implementation of pwn1sher's KillDefender
Octoberfest7/lnk_generator
Small project to facilitate creation of .lnk payloads
Octoberfest7/Presentations
Slide decks and/or materials from conference presentations
Octoberfest7/CS_Uploads_Tracker
Aggressor script add-in for CobaltStrike to track file uploads
Octoberfest7/KillDefender
A small (Edited) POC to make defender useless by removing its token privileges and lowering the token integrity
Octoberfest7/Proxy_Egress_Persistence
A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies
Octoberfest7/aggressor_snippets
A collection of random small Aggressor snippets that don't warrant their own repo
Octoberfest7/Backstab_BOF
Beacon Object File implementation of Yaxser's Backstab
Octoberfest7/Shoggoth
Shoggoth: Asmjit Based Polymorphic Encryptor
Octoberfest7/Octoberfest7
Octoberfest7/SC_DEMO