# trustedsec/CS-Remote-OPs-BOF

Remote operations commands implemented using Beacon Object Files

Repository: https://github.com/trustedsec/CS-Remote-OPs-BOF
Canonical: https://ross.abutalabs.com/products/cs-remote-ops-bof
Language: C
License: GPL-2.0
License Family: copyleft
Last push: 2026-07-20T16:51:29+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 93, release rhythm 93, longevity 100
- inputs: {"age_days": 1591, "days_push": 44, "days_rel": 44, "gap_med": 9, "n_releases_24m": 10}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1183, forks 175 (observed 2026-08-28T04:03:54.543288+00:00)

## What it is
A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like user management, token manipulation, ADCS certificate requests, scheduled tasks, and credential extraction. It also includes injection BOFs used for EDR detection testing.

## Use cases
- run post-exploitation commands on remote Windows hosts from Cobalt Strike
- request ADCS enrollment certificates during a red team engagement
- add or disable user accounts on a remote machine via a BOF
- extract Office JWT tokens and browser-stored credentials from memory
- test EDR detection coverage against process injection techniques
- impersonate users with certificate-based make_token
- create scheduled tasks on remote hosts for persistence

## When to choose
- you operate Cobalt Strike and want ready-made remote operations BOFs
- you need lightweight in-memory Windows primitives without dropping binaries to disk
- you are building or extending a red team toolchain with BOF-based commands
- you want to validate EDR detections against common offensive techniques

## When to avoid
- you need a supported, production-grade tool - injection BOFs are explicitly unsupported
- you are not using Cobalt Strike or a BOF-compatible agent
- you need defensive or purely situational-awareness tooling (see CS-Situational-Awareness-BOF instead)
- your use case is unauthorized access to systems you do not own or have permission to test

## Facets
- artifact type: library
- maturity: active
- function: security, developer-tools, cli
- domain: security, penetration-testing, windows
- platform: windows, cpp
- tags: cobalt-strike, beacon-object-file, bof, red-team, offensive-security, post-exploitation, credential-access, privilege-escalation, persistence, edr-testing

## Member repositories
- trustedsec/CS-Remote-OPs-BOF (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:54.543288+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:24:40.025705+00:00, confidence not recorded.
  - readme: https://github.com/trustedsec/CS-Remote-OPs-BOF (fetched 2026-08-28T04:03:54.543288+00:00, sha fe2ecbda2f07)
- Data as of 2026-08-30T08:39:29.467469+00:00.
