
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

WIP Post-exploitation framework tailored for hypervisors.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.

Post-authentication remote code execution proof-of-concept for CVE-2025-49113 in Roundcube webmail. Includes a vulnerable Docker environment and…

DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.

POC for utilizing wikipedia API for Command and Control

The code for personally reproducing the corresponding vulnerability

Python exploit for CVE-2026-23744 achieving remote code execution via crafted POST requests to the /api/mcp/connect endpoint in MCPJam Inspector <=…

Encrypted push-to-talk voice and text communication over Tor hidden services with end-to-end encryption, configurable ciphers, relay mode for group…

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Mythic C2 profile that tunnels Athena and Apollo agent traffic through Telegram bot-to-bot messages, bridging encrypted payloads to Mythic via its…

Proof-of-concept exploit for CVE-2022-30525 enabling unauthenticated remote command injection on Zyxel firewalls via HTTP POST requests to the…

Unauthenticated OS command injection exploit for InSAT MasterSCADA BUK-TS MMadmServ web interface. Delivers reverse shell with root privileges via…

Python exploit script for CVE-2024-25180, a remote code execution vulnerability in pdfmake, delivering a reverse shell via crafted POST requests.

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…