
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)

My experiments in weaponizing Nim (https://nim-lang.org/)

Windows Event Log Killer

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…


Venom is a library that meant to perform evasive communication using stolen browser socket

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

An interactive shell to spoof some LOLBins command line

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.