
CVE-2021-40444
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

PowerShell Ransomware Simulator with C2 Server

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

Build a basic Command & Control botnet in C

Python Remote Administration Tool (RAT) to gain meterpreter session

Automated Tactics Techniques & Procedures

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…


Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

Exploit for CVE-2025-55182 & CVE-2025-66478