
ScreenshotBOF
An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Mac OS Trojan (RAT) made with love <3

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

PyRat,a rat by python xmlrpc

poc for CVE-2025-24252 & CVE-2025-24132

golang script for bypass AV and work only in windows platform

参考Gh0st源码,实现的一款PC远程协助软件,拥有远程Shell、文件管理、桌面管理、消息发送等功能。

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Reverse shell generator written in Python 3.

macOS Initial Access Payload Generator

Notion as a platform for offensive operations


Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

A fully featured backdoor that uses Twitter as a C&C server

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

Hide your payload into .jpg file

Modern PIC implant for Windows (64 & 32 bit)