
XSS2Shell
Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Various Cobalt Strike BOFs

Simple BOF to read the protection level of a process

PowerShell rebuilt in C# for Red Teaming purposes

Abusing Azure services over C2

Hooked browser communication over MQTT

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

F5 BIG-IP RCE CVE-2020-5902 automatic check tool

LSTAR - CobaltStrike 综合后渗透插件

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Phase C&C Blind SQL Injection

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

Is this IP a C2 server?

complex webshell manager, quasi-http botnet.

Work in Progress. RAT written in C++ using wxWidgets