
proofpoint-CVE-2023-0089
Proofpoint Email Gateway: Low level authenticated user to admin RCE

Proofpoint Email Gateway: Low level authenticated user to admin RCE

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Socks proxy, and reverse socks server using powershell.

SSHPry v2 - Spy & Control os SSH Connected client's TTY

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Multiplayer pivoting solution

Network Pivoting Toolkit

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

Miscellaneous Tools

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

A basic emulation of an "RPC Backdoor"

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.