
CarbonCopy
A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
Tools for creating and customizing malicious code or instructions to execute after exploitation.

A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux


HTA encryption tool for RedTeams

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

generate CobaltStrike's cross-platform payload

The Shadow Attack Framework

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…

venom - C2 shellcode generator/compiler/handler

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

RedSnarf is a pen-testing / red-teaming tool for Windows environments

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

XSS payloads designed to turn alert(1) into P1

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Python botnet and backdoor

A post exploitation framework designed to operate covertly on heavily monitored environments

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell