
Empire
Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

A third-party Gopher Assassin for the Havoc Framework.

C2 redirector base on caddy

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

A Zeek based Mitre Caldera detector.


Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

JavaScript for Automation (JXA) macOS agent

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Post Exploitation agent which uses a browser to do C2 operations.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Git Web Hook Tunnel for C2

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…