Ross ROSS = Recommend OSS · open-source software intelligence for agents

trustedsec/CS-Remote-OPs-BOF

Remote operations commands implemented using Beacon Object Files observed · 2026-08-28

github.com/trustedsec/CS-Remote-OPs-BOF · C · GPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 93
  • Release rhythm 93
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 9
  • age_days: 1591
  • days_rel: 44
  • days_push: 44
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

1183 stars · 175 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like user management, token manipulation, ADCS certificate requests, scheduled tasks, and credential extraction. It also includes injection BOFs used for EDR detection testing.

Use cases

  • run post-exploitation commands on remote Windows hosts from Cobalt Strike
  • request ADCS enrollment certificates during a red team engagement
  • add or disable user accounts on a remote machine via a BOF
  • extract Office JWT tokens and browser-stored credentials from memory
  • test EDR detection coverage against process injection techniques
  • impersonate users with certificate-based make_token
  • create scheduled tasks on remote hosts for persistence

When to choose

  • you operate Cobalt Strike and want ready-made remote operations BOFs
  • you need lightweight in-memory Windows primitives without dropping binaries to disk
  • you are building or extending a red team toolchain with BOF-based commands
  • you want to validate EDR detections against common offensive techniques

When to avoid

  • you need a supported, production-grade tool - injection BOFs are explicitly unsupported
  • you are not using Cobalt Strike or a BOF-compatible agent
  • you need defensive or purely situational-awareness tooling (see CS-Situational-Awareness-BOF instead)
  • your use case is unauthorized access to systems you do not own or have permission to test

Facets

library · maturity active

security developer-tools cli security penetration-testing windows windows cpp cobalt-strike beacon-object-file bof red-team offensive-security post-exploitation credential-access privilege-escalation persistence edr-testing

1 source

Member repositories

RepositoryRoleHealth v2
trustedsec/CS-Remote-OPs-BOFmain94

For agents

markdown · JSON · MCP: product_card(name="trustedsec/CS-Remote-OPs-BOF")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem