
CVE-2026-10520
Root-Level RCE via OS Command Injection in Ivanti Sentry

Root-Level RCE via OS Command Injection in Ivanti Sentry

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Socks proxy, and reverse socks server using powershell.

Network Pivoting Toolkit

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Miscellaneous Tools

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

SSHPry v2 - Spy & Control os SSH Connected client's TTY

Multiplayer pivoting solution

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

A basic emulation of an "RPC Backdoor"

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.