
DNS_Tunneling
DNS tunneling tool using PowerShell and Nslookup to exfiltrate data and deliver payloads via DNS TXT/MX records, bypassing Constrained Language Mode…

DNS tunneling tool using PowerShell and Nslookup to exfiltrate data and deliver payloads via DNS TXT/MX records, bypassing Constrained Language Mode…

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering

Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)

A collection of tools for dealing with TrickBot

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Database components for RCS backend

A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell…

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

WIP Post-exploitation framework tailored for hypervisors.

Post-exploitation framework that abuses trusted sites like Telegram and Discord for C2.