cpp-bof
Audited by Socket on Apr 16, 2026
4 alerts found:
Anomalyx3MalwareThis fragment is a BOF/C2-oriented template (Beacon Object File) that parses untrusted arguments and logs them, allocates and frees a heap buffer, and contains no implemented payload logic in the provided snippet. While there is no direct malicious behavior demonstrated here, the context strongly suggests it is intended to be embedded in offensive tooling; additional malicious actions would likely appear in the `/* Your logic here */` section. Risk is therefore moderate (template/context risk) rather than a confirmed malware implementation in this exact code fragment.
This module is primarily a build wrapper that compiles attacker-supplied C++ into a Windows BOF-oriented object using a packaged beacon.h interface and then strips it for size/visibility reduction. The immediate code has no networking, persistence, or execution of the produced payload. The main security concern is that it enables compilation of arbitrary code into an offensive-purpose artifact, and it writes to a caller-influenced output path without validation (build-time supply-chain risk and potential misuse depending on how the package is distributed/used).
This fragment is a Cobalt Strike Beacon BOF API header. It contains no executable implementation, credentials, domains, or direct sabotage logic. However, it declares numerous offensive capabilities (process injection, token manipulation, remote memory read/write, low-level syscall wrappers, and payload download handling). The security risk is primarily contextual: if used by BOF payloads, it can enable post-exploitation actions. Review the corresponding BOF implementation files that call these APIs to determine whether actual malicious behavior occurs.
The skill is internally consistent, but its stated purpose is offensive: it equips an AI agent to build Cobalt Strike BOFs with screenshot capture and Beacon-based file exfiltration. This is not a benign developer guide; it materially enables post-exploitation malware/C2 operations, so it should be treated as high risk.