
phpsploit
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Adversary Emulation Framework

link is a command and control framework written in rust

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

MCP Server for Metasploit

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback

React2Shell Exploitation Tool (CVE-2025-55182)

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus

C2 tool routing Cobalt Strike beacon data over LDAP user attributes for stealthy command-and-control in segmented networks.