{"id":13840027,"url":"https://github.com/tomcarver16/BOF-DLL-Inject","last_synced_at":"2025-07-11T07:31:50.325Z","repository":{"id":202438994,"uuid":"292698152","full_name":"tomcarver16/BOF-DLL-Inject","owner":"tomcarver16","description":"Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files.","archived":false,"fork":false,"pushed_at":"2020-09-03T23:24:31.000Z","size":20,"stargazers_count":146,"open_issues_count":2,"forks_count":22,"subscribers_count":6,"default_branch":"master","last_synced_at":"2024-08-05T17:24:37.141Z","etag":null,"topics":["bof","cobalt-strike","cobaltstrike","dll-injection","red-teaming","redteam"],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tomcarver16.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2020-09-03T23:04:30.000Z","updated_at":"2024-07-17T14:30:50.000Z","dependencies_parsed_at":"2024-04-17T10:01:29.852Z","dependency_job_id":null,"html_url":"https://github.com/tomcarver16/BOF-DLL-Inject","commit_stats":null,"previous_names":["tomcarver16/bof-dll-inject"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tomcarver16%2FBOF-DLL-Inject","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tomcarver16%2FBOF-DLL-Inject/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tomcarver16%2FBOF-DLL-Inject/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tomcarver16%2FBOF-DLL-Inject/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tomcarver16","download_url":"https://codeload.github.com/tomcarver16/BOF-DLL-Inject/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225705148,"owners_count":17511232,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bof","cobalt-strike","cobaltstrike","dll-injection","red-teaming","redteam"],"created_at":"2024-08-04T17:00:40.807Z","updated_at":"2024-11-21T09:30:44.728Z","avatar_url":"https://github.com/tomcarver16.png","language":"C","funding_links":[],"categories":["C (286)","C"],"sub_categories":[],"readme":"# BOF-DLL-Inject\nBOF DLL Inject is a custom [Beacon Object File](https://www.cobaltstrike.com/help-beacon-object-files) that uses manual map \nDLL injection in order to migrate a dll into a process all from memory. \n\n## Advantages\n- Less likely to be signatured\n- DLL payload stays in memory and never touches disk\n- Additional functionality is easy to implement\n- DLL isn't registered as a module including the EPROCESS structure in kernel land\n\n## Notes\nTo see how I developed this tool and further information on it see my blog [post](https://x64sec.sh/custom-dll-injection-with-cobalt-strike/)\n\n![Cobalt Strike BOF Executing](cobalt-strike-mandll.png \"Cobalt Strike mandll\")","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftomcarver16%2FBOF-DLL-Inject","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftomcarver16%2FBOF-DLL-Inject","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftomcarver16%2FBOF-DLL-Inject/lists"}