# outflanknl/C2-Tool-Collection

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Repository: https://github.com/outflanknl/C2-Tool-Collection
Canonical: https://ross.abutalabs.com/products/c2-tool-collection
Language: C
License Family: other
Last push: 2023-10-27T14:16:17+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1594, "days_push": 1041, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1415, forks 215 (observed 2026-08-28T04:04:39.773644+00:00)

## What it is
A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) and reflective DLL loading. It includes tools for Active Directory enumeration, privilege escalation exploits, credential dumping, and host reconnaissance used in red team operations.

## Use cases
- run red team post-exploitation tools through Cobalt Strike
- enumerate Active Directory domain info from a beacon
- exploit CVE-2022-26923 ADCS privilege escalation
- kerberoast service accounts and dump LAPS passwords
- detect installed EDR/AV products on a target host
- add rogue machine accounts in Active Directory
- load offensive tools via BOF or reflective DLL

## When to choose
- you run Cobalt Strike or a compatible C2 framework and need BOF tooling
- you need AD-focused post-exploitation and recon tools written in C
- you want community-maintained red team tooling from a reputable security firm

## When to avoid
- you need a standalone tool that works without a C2 framework
- you require a maintained license or official support
- you need defensive-only tooling rather than offensive capabilities

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, cli
- domain: security, penetration-testing, developer-tools
- platform: windows, cli
- tags: red-team, cobalt-strike, bof, beacon-object-files, reflective-dll, ad-exploitation, c2-frameworks, offensive-security

## Member repositories
- outflanknl/C2-Tool-Collection (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:39.773644+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:38:09.951156+00:00, confidence not recorded.
  - readme: https://github.com/outflanknl/C2-Tool-Collection (fetched 2026-08-28T04:04:39.773644+00:00, sha 80d21b9643f8)
- Data as of 2026-08-30T08:39:29.467469+00:00.
