
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

Automated Attack Simulation in the Cloud, complete with detection use cases.

Go-based proof-of-concept exploit for CVE-2023-5044 in ingress-nginx, enabling authenticated remote command execution by creating crafted Kubernetes…

Cloud-based attack emulation framework for executing offensive techniques and generating repeatable detection samples across AWS and GCP via a UI or…

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Red Team K8S Adversary Emulation Based on kubectl

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

A proof of concept demonstrating the use of Google Drive for command and control.