
CVE-2025-50505
Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

VMware Aria Operations for Logs CVE-2023-34051

Dominate Active Directory with PowerShell.

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Automated 802.1x Bypass

A Bypass Anti-virus Software Lateral Movement Command Execution Tool

CVE-2025-33073

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Fileless Command Execution for Lateral Movement in Nim

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

A Golang implant that uses Slack as a command and control server

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

A basic emulation of an "RPC Backdoor"

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.