#1Adversary simulation, red team infrastructure, C2 frameworks, and operational security tools.
Kitploit recommended


Zimbra <9.0.0.p27 RCE

Aggressor Script to launch IE driveby for CVE-2018-4878

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Kali365 - EvilTokens Replica

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Python api for usage with cobalt strike's External C2 specification

Zimbra RCE simple poc

Slui File Handler Hijack UAC Bypass Local Privilege Escalation

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Сollection of TCL scripts for Cisco IOS penetration testing

Security Research

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.