
CVE-2025-52136
Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

A basic emulation of an "RPC Backdoor"

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Open Source C&C Specification

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Penetration testing framework with AI-driven decision engine

MeshDeck port for Arch Linux ARM - Wilson

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

C&C Botnet written in Python with fabric

A Windows Remote Administration Tool in Visual Basic with UNC paths

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

The DCERPC only printerbug.py version

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…