
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Community payload loaders, scripts, and configurations for Brute Ratel C4, supporting red team command-and-control operations and payload deployment.

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

A cross platform C2/post-exploitation framework.

Builds a trojanized .jpg.exe agent that downloads and executes a user-supplied PowerShell, Batch, or Metasploit payload, then opens a Meterpreter…

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

Curated proof-of-concept implementations of malware TTPs, covering persistence, privilege escalation, command-and-control, and post-exploitation for…

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…


External C2 framework in Rust that executes commands on Linux, macOS, and Windows implants through VirusTotal and Mastodon APIs with AES-encrypted…

Legacy Windows RAT source code with client/server backdoor architecture, configurable payload builder, and full remote control for malware research.

Tools for maintaining access to systems and proof-of-concept demonstrations.

Modern PIC implant for Windows (64 & 32 bit)

A Rust template for writing Beacon Object Files (BOFs)

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

Red team ransomware simulator with custom payload generation, centralized C2 dashboard, and file encryption/decryption for penetration testing.

Windows persistence technique using AddMonitor to load a malicious DLL with SYSTEM privileges, enabling remote C2 via Meterpreter.