outflanknl/C2-Tool-Collection logo

outflanknl/C2-Tool-Collection

Free

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

FreeFree tier
Type
Open Source

About outflanknl/C2-Tool-Collection

Outflank's C2 Tool Collection is a repository of tools designed for red team operations, integrating with Cobalt Strike via Beacon Object Files (BOF) and reflective DLL loading. The collection includes utilities for Active Directory enumeration, Kerberos attacks, LAPS dumping, process inspection, and more. Tools are used by Outflank team members and are contributed to the community as open-source.

Key Features

Beacon Object File (BOF) integration for Cobalt Strike
Reflective DLL loading capabilities
Active Directory enumeration and abuse (AddMachineAccount, Domaininfo, ReconAD)
Kerberos attacks (Kerberoast, KerbHash, SprayAD)
LAPS password dumping (Lapsdump)
PetitPotam exploit implementation (BOF and reflective DLL)
Process and kernel enumeration (Psc, Psx, Psk)
Credential harvesting via social engineering (Askcreds)
Remote named pipe enumeration (RemotePipeList)

Pros & Cons

Pros
  • Free and open-source, with active community contributions from red team experts
  • Covers a wide range of techniques: AD abuse, credential harvesting, process enumeration, and exploits
  • Well-documented with individual README files for each tool
  • Includes both BOF and reflective DLL implementations for flexibility
  • Actively used in real red team engagements by the developers
Cons
  • Primarily designed for Cobalt Strike; integration with other C2 frameworks may be limited
  • Some tools require specific build environments or dependencies (e.g., Visual Studio, .NET)
  • Not all tools may be actively maintained, and updates are provided on a best-effort basis

Best For

Red team assignments for simulated adversarial operationsActive Directory security assessments and penetration testingCredential security testing through Kerberos and LDAP attacksWindows process and kernel visibility for threat detection evaluationLateral movement and privilege escalation technique validation