
SpotifyC2
Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

Exploit created by: R4v3nBl4ck end Pacman

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

a guard that blocks catastrophic agent actions

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

How to spoof the command line when spawning a new process from C#.

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs


LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Script is a proof of concept how to control your machine by using social media sites.

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2