
evil-winrm-py
Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

Easy files and payloads delivery over DNS

Wiki to collect Red Team infrastructure hardening resources

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

This repository is a collection of powershell functions every hacker should know

Curated collection of offensive security tools and commands for Active Directory attacks, C2, privilege escalation, obfuscation, and web pentesting.

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

This is a plugin for the c# R.A.T server providing extension to android based phone systems

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

A simple, extensible C&C beaconing system.

Reverse engineered android malware, and this is a C&C server for it

pinky - The PHP mini RAT (Remote Administration Tool)

Remote Administration Tool for Android devices

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…