
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Ping Exfiltration Command and Control (PiX-C2)

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

Hunts out CobaltStrike beacons and logs operator command output

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

A PoC Java Stager which can download, compile, and execute a Java file in memory.

ICMP-based command-and-control tool that tunnels C2 traffic through firewalls using ping payloads, undetectable by most AV/EDR solutions.

Malleable C2 profiles for Cobalt Strike

Apfell C2 Server for the Google Chrome Extension Payload

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

CVE-2019-12949

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…