<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Extension-Kit on JustC2 Docs</title><link>/en/docs/extension-kit/</link><description>Recent content in Extension-Kit on JustC2 Docs</description><generator>Hugo</generator><language>en</language><copyright>Copyright (c) 2026 JustC2</copyright><lastBuildDate>Sun, 20 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="/en/docs/extension-kit/index.xml" rel="self" type="application/rss+xml"/><item><title>SAL-BOF — Local Reconnaissance</title><link>/en/docs/extension-kit/sal-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/sal-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;SAL-BOF&lt;/strong&gt; (Situational Awareness — Local) module provides commands to gather information from the local system where the agent is running. These commands should be the first you run after gaining access to a machine to understand the environment before taking any further action.&lt;/p&gt;</description></item><item><title>SAR-BOF — Remote Reconnaissance</title><link>/en/docs/extension-kit/sar-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/sar-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;SAR-BOF&lt;/strong&gt; (Situational Awareness — Remote) module provides commands for network reconnaissance and remote system enumeration. These commands allow mapping the network, identifying active hosts, and discovering lateral movement targets, all from the agent without external tools.&lt;/p&gt;</description></item><item><title>Creds-BOF — Credential Extraction</title><link>/en/docs/extension-kit/creds-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/creds-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;Creds-BOF&lt;/strong&gt; module provides tools for credential extraction on Windows systems. It includes techniques ranging from social engineering to LSASS memory dumping, covering scenarios with both standard user and administrator privileges.&lt;/p&gt;</description></item><item><title>Process-BOF</title><link>/en/docs/extension-kit/process-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/process-bof/</guid><description>&lt;p&gt;Process-BOF provides commands for inspecting, analyzing, and controlling processes on the compromised system. These commands are essential for pre-injection reconnaissance, identifying sensitive processes, and temporarily controlling security processes.&lt;/p&gt;</description></item><item><title>Injection-BOF</title><link>/en/docs/extension-kit/injection-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/injection-bof/</guid><description>&lt;p&gt;Injection-BOF provides multiple shellcode injection techniques into remote processes. From classic section-based techniques to advanced PoolParty techniques that abuse Windows Thread Pool internals for EDR evasion.&lt;/p&gt;</description></item><item><title>Postex-BOF</title><link>/en/docs/extension-kit/postex-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/postex-bof/</guid><description>&lt;p&gt;Postex-BOF provides utilities for post-exploitation operations: firewall manipulation, screenshots, and advanced sensitive file searching on the compromised system.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Compatible agents:&lt;/strong&gt; Beacon, Gopher, Kharon | &lt;strong&gt;Platform:&lt;/strong&gt; Windows&lt;/p&gt;</description></item><item><title>Elevation-BOF</title><link>/en/docs/extension-kit/elevation-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/elevation-bof/</guid><description>&lt;p&gt;Elevation-BOF provides multiple techniques for escalating privileges on Windows systems. From obtaining SYSTEM tokens to UAC bypass and Potato-style attacks for service accounts.&lt;/p&gt;</description></item><item><title>Lateral Movement</title><link>/en/docs/extension-kit/lateral-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/lateral-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;LateralMovement-BOF&lt;/strong&gt; module provides commands for moving from a compromised machine to others within the network. It includes remote execution techniques, security token manipulation, and execution as other users.&lt;/p&gt;</description></item><item><title>Code Execution</title><link>/en/docs/extension-kit/execution-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/execution-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;Execution-BOF&lt;/strong&gt; module provides two mechanisms for executing arbitrary code in the agent&amp;rsquo;s process memory, without writing any files to disk on the target machine.&lt;/p&gt;</description></item><item><title>AD-BOF — Active Directory</title><link>/en/docs/extension-kit/ad-bof/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>/en/docs/extension-kit/ad-bof/</guid><description>&lt;p&gt;The &lt;strong&gt;AD-BOF&lt;/strong&gt; module provides fundamental tools for interacting with Active Directory during an authorized pentest engagement. It includes LDAP reconnaissance commands, credential extraction via DCSync, LAPS password reading, and WebDAV service manipulation.&lt;/p&gt;</description></item></channel></rss>