
CoffeeLdr
Loads and executes Cobalt Strike Beacon Object Files outside the framework, enabling custom implants and standalone testing of BOF payloads.

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

A native backdoor module for Microsoft IIS (Internet Information Services)

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

Modular RAT/C2 framework supporting DNS and TCP transports with staged payload delivery, file transfer, socket sharing, and PowerShell agent…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

🔥 CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Python-based RAT with a web-based C2 server and cross-platform agent builder. Supports remote shell execution, file transfer, screenshot capture,…

Use a Fake image.jpg to exploit targets (hide known file extensions)

PowerShell-based reverse TCP shell framework with C2 server modules for remote host control, file transfer, and screenshot capture during penetration…

A fully featured backdoor that uses Twitter as a C&C server

PowerShell Remote Download Cradle Generator & Obfuscator