bof-dev

Installation
SKILL.md

bof-dev

Goal: Write stealthy, production-ready Beacon Object Files (BOFs) in C or C++ for Cobalt Strike, Sliver, Havoc, or custom COFF loaders.

Cognitive Stance

A BOF is just an unlinked object file (.o / .obj). The loader maps sections into memory and links it at runtime. It has no OS loader, no runtime (CRT/STL), and exits via go().

Strict Rules

  1. No Standard Library / Runtime: No printf, malloc, new, std::string, try/catch.
  2. DFR (Dynamic Function Resolution): You must declare DECLSPEC_IMPORT and use KERNEL32$VirtualAlloc format so the loader can resolve Win32 APIs statically. Do not link against kernel32.lib.
  3. Global State: Global initialized variables (int x = 5;) are mapped but remain persistent across BOF executions in the same process. Use them cautiously. Global C++ constructors (Foo f;) will fail to link.
  4. C++ Specifics: Strip all C++ features that require runtime support. Disable RTTI (-fno-rtti) and exceptions (-fno-exceptions). The entry point go must be declared extern "C".
  5. Memory Safety: You are executing inside the C2 agent's process. A segfault kills the payload. Check all pointers. Use BeaconPrintf for output.

Framework Constraints (Mingw-w64)

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
bof-dev — aeondave/malskill