
CVE-2025-43920
PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Proof-of-concept for CVE-2026-4480, a Samba print job name command injection vulnerability. Demonstrates exploitation via malicious print job names…

A library for integrating communication channels with the Cobalt Strike External C2 server

Python api for usage with cobalt strike's External C2 specification

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

CobaltStrike External C2 for Websockets

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

A framework for constructing self-spreading binaries

Python api for usage with cobalt strike's External C2 specification

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

Docker projects to retain beacon source IPs using C2 relaying infra