{"adoption": {"forks": 175, "observed_at": "2026-08-28T04:03:54.543288+00:00", "stars": 1183}, "canonical_url": "https://ross.abutalabs.com/products/cs-remote-ops-bof", "card": {"archived": false, "artifact_type": "library", "description": "Remote operations commands implemented using Beacon Object Files", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "developer-tools", "cli"], "health_score": 96, "homepage": null, "language": "C", "license": "GPL-2.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["trustedsec/CS-Remote-OPs-BOF"], "name": "trustedsec/CS-Remote-OPs-BOF", "platform": ["windows", "cpp"], "pushed_at": "2026-07-20T16:51:29+00:00", "repo": "trustedsec/CS-Remote-OPs-BOF", "stars": 1183, "tags": ["cobalt-strike", "beacon-object-file", "bof", "red-team", "offensive-security", "post-exploitation", "credential-access", "privilege-escalation", "persistence", "edr-testing"], "topics": [], "urls": [], "use_cases": ["run post-exploitation commands on remote Windows hosts from Cobalt Strike", "request ADCS enrollment certificates during a red team engagement", "add or disable user accounts on a remote machine via a BOF", "extract Office JWT tokens and browser-stored credentials from memory", "test EDR detection coverage against process injection techniques", "impersonate users with certificate-based make_token", "create scheduled tasks on remote hosts for persistence"], "what_it_is": "A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like user management, token manipulation, ADCS certificate requests, scheduled tasks, and credential extraction. It also includes injection BOFs used for EDR detection testing.", "when_to_avoid": ["you need a supported, production-grade tool - injection BOFs are explicitly unsupported", "you are not using Cobalt Strike or a BOF-compatible agent", "you need defensive or purely situational-awareness tooling (see CS-Situational-Awareness-BOF instead)", "your use case is unauthorized access to systems you do not own or have permission to test"], "when_to_choose": ["you operate Cobalt Strike and want ready-made remote operations BOFs", "you need lightweight in-memory Windows primitives without dropping binaries to disk", "you are building or extending a red team toolchain with BOF-based commands", "you want to validate EDR detections against common offensive techniques"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/cs-remote-ops-bof", "repo": "trustedsec/CS-Remote-OPs-BOF", "role": "main", "score": 94}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:54.543288+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:24:40.025705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fe2ecbda2f0783bb839a9ffc97c734e6dbaa27737e93fe719eb2d1c0663facbd", "fetched_at": "2026-08-28T04:03:54.543288+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Remote-OPs-BOF"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 93, "longevity": 100, "rhythm": 93}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1591, "days_push": 44, "days_rel": 44, "gap_med": 9, "n_releases_24m": 10}, "score": 94, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}