c-bof
Audited by Socket on Apr 16, 2026
2 alerts found:
AnomalySecurityThis fragment is a Cobalt Strike Beacon BOF API header. It contains no executable implementation, credentials, domains, or direct sabotage logic. However, it declares numerous offensive capabilities (process injection, token manipulation, remote memory read/write, low-level syscall wrappers, and payload download handling). The security risk is primarily contextual: if used by BOF payloads, it can enable post-exploitation actions. Review the corresponding BOF implementation files that call these APIs to determine whether actual malicious behavior occurs.
High-risk offensive skill. Its purpose and capabilities are internally consistent, but that purpose is to help an AI agent create and refine Cobalt Strike BOFs for process injection, credential access, keylogging, dumping, and exfiltration-adjacent workflows. No clear malicious installer or hidden credential theft is present, so this is not confirmed malware, but it is a dangerous exploit-oriented capability set and should be classified as suspicious/high-risk.