5.2 KiB
inline_execute - Execute Beacon Object File (BOF)
Execute a Beacon Object File (BOF) in the current process thread and capture its output.
Description
The inline_execute command loads and executes a COFF (Common Object File Format) file, commonly known as a Beacon Object File (BOF), directly in the memory of the current process. BOFs are lightweight, position-independent code objects that can be executed without creating new processes, making them useful for stealthy operations.
Syntax
inline_execute -BOF <bof_file> [-Arguments <arguments>]
Parameters
-BOForbof_name(required): Name of an already uploaded BOF file (e.g.,whoami.x64.o)bof_file(required for new uploads): A new BOF file to upload and execute-Argumentsorbof_arguments(optional): Arguments to pass to the BOF
Argument Types
BOF arguments can be specified using the following format:
int16:123or-s:123- 16-bit integerint32:1234or-i:1234- 32-bit integerstring:helloor-z:hello- Null-terminated stringwchar:helloor-Z:hello- Wide character stringbase64:abc==or-b:abc==- Base64-encoded binary data
Examples
# Execute a BOF with no arguments
inline_execute -BOF whoami.x64.o
# Execute a BOF with integer argument
inline_execute -BOF listmods.x64.o -Arguments int32:1234
# Execute a BOF with multiple arguments
inline_execute -BOF netstat.x64.o -Arguments int32:4 string:TCP
# Upload and execute a new BOF
inline_execute -BOF custom_bof.x64.o -Arguments int32:5678
Features
- In-Memory Execution: BOFs are executed directly in the current process memory without creating new processes
- COFF Loader: Full COFF loader implementation supporting x64 BOFs with relocations and symbol resolution
- Beacon API Compatibility: Compatible with Cobalt Strike BOF API (BeaconPrintf, BeaconOutput, etc.)
- Output Capture: Automatically captures and returns BOF output
- Argument Parsing: Supports multiple argument types (int16, int32, string, wchar, base64)
Output
The command returns the output captured from the BOF via BeaconPrintf or BeaconOutput:
[BOF Output]
Module Name: ntdll.dll
Base Address: 0x7ffa12340000
Size: 0x1f0000
If the BOF produces no output, the command will indicate successful execution.
OPSEC Considerations
- MEDIUM OPSEC RISK: In-process execution reduces some detection vectors compared to process spawning
- Process Create Artifact: BOF execution creates a "Process Create" artifact that is logged in Mythic
- Memory Allocation: BOFs allocate executable memory (PAGE_EXECUTE_READWRITE) which may be detected by EDR solutions
- API Monitoring: External symbol resolution (LoadLibraryA, GetProcAddress) may be logged by EDR/XDR
- Memory Scanning: Allocated executable memory may be scanned by EDR memory protection features
- No New Process: Unlike
shell, BOFs execute in-process, reducing some detection vectors - Thread Isolation: BOFs execute in a separate thread with a 30-second timeout to prevent agent crashes
Technical Details
COFF Loader
The COFF loader implementation:
- Supports x64 COFF files (IMAGE_FILE_MACHINE_AMD64)
- Handles relocations (IMAGE_REL_AMD64_ADDR64, IMAGE_REL_AMD64_ADDR32NB, IMAGE_REL_AMD64_REL32)
- Resolves internal Beacon API functions
- Resolves external symbols via LoadLibraryA/GetProcAddress
- Maps sections with PAGE_EXECUTE_READWRITE permissions
Thread Isolation
BOFs are executed in a separate thread to prevent agent crashes:
- Timeout: 30-second timeout for BOF execution
- Thread Termination: If BOF hangs, the thread is terminated after timeout
- Output Capture: Output is captured even if BOF hangs or times out
- Agent Stability: Main agent thread continues to function even if BOF crashes
Beacon API Compatibility
The following Beacon API functions are supported:
BeaconPrintf- Formatted output (captured and returned)BeaconOutput- Raw output (captured and returned)BeaconDataParse- Parse input dataBeaconDataInt,BeaconDataShort,BeaconDataExtract- Data extractionBeaconUseToken,BeaconRevertToken- Token manipulationBeaconIsAdmin- Admin check
Argument Serialization
Arguments are serialized using the Packer class format:
- Each argument is prefixed with its size (4 bytes, little-endian)
- Arguments are packed sequentially:
[size:4][data][size:4][data]... - The total buffer size is prepended to the argument buffer
- Boolean values are converted to integers (0 or 1) before serialization
Error Handling
The command handles various error scenarios:
- File Not Found: Returns error if BOF file cannot be retrieved from Mythic
- Invalid COFF: Returns error if file is not a valid COFF or unsupported architecture
- Symbol Resolution Failure: Warns if external symbols cannot be resolved
- Execution Failure: Returns error if BOF entry point cannot be found or execution fails
Related
inline_execute_assembly- Execute .NET assemblies in-process- Artifacts Support
Command Category: Execution & Control
Requires Admin: No
MITRE ATT&CK: T1055 - Process Injection