
RedGhost
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

VMware Aria Operations for Logs CVE-2023-34051

Automated 802.1x Bypass

CVE-2025-33073

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Fileless Command Execution for Lateral Movement in Nim

BOF POC of the DSCourier project / invoking WinGet via COM

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

A Bypass Anti-virus Software Lateral Movement Command Execution Tool

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

Penetration testing framework with AI-driven decision engine

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.