#1Tools for maintaining long-term access to compromised systems, even after reboots.
Kitploit recommended

LD_PRELOAD shared library that hides a Linux process from tools like ps and lsof by intercepting readdir and proc filesystem calls.

PowerSploit - A PowerShell Post-Exploitation Framework

Empire is a PowerShell and Python post-exploitation agent.

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

C# toolkit for establishing and managing Windows persistence via registry keys, scheduled tasks, services, startup folders, KeePass configs, and…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Python antivirus evasion tool

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

C2/post-exploitation framework

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

A simple remote tool in C#.

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

DNS covert channel implant for Red Teams.

Remote administration service which uses twitter as a command and control server

Windows Remote Administration Tool via Telegram