
RPC-Backdoor
A basic emulation of an "RPC Backdoor"

A basic emulation of an "RPC Backdoor"

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

xll windows reverse shell

A fully featured Windows backdoor that uses email as a C&C server

C&C Botnet written in Python with fabric

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Ping Exfiltration Command and Control (PiX-C2)

Miscellaneous Tools

RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

Proofpoint Email Gateway: Low level authenticated user to admin RCE

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…