
KittyStager
KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Cobalt Strike HTTPS beaconing over Microsoft Graph API

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

Protocol agnostic online password guessing API.

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

Simple JMX RMI scanning tool

IP obfuscator made to make a malicious ip a bit cuter

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers

Zimbra RCE simple poc

DNS over HTTPS targeted malware (only runs once)

A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Command and Control server on Slack

A simple tool to interact with web shells and command injection vulnerabilities