
wraith
Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Android remote administration tool

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Deprecated - Low Orbit Ion Cannon - An open source network stress tool, written in C#. Based on Praetox's LOIC project. USE ON YOUR OWN RISK. WITHOUT…

LSTAR - CobaltStrike Translated to EN

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injection through the Webmin's File Manager feature

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injetion through the Webmin's Upload and Download feature

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Small backdoor using cookie.

Exploit for CVE-2020-15778(OpenSSH vul)