
CIMplant
C# port of WMImplant which uses either CIM or WMI to query remote systems

C# port of WMImplant which uses either CIM or WMI to query remote systems

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

A HTA shell to assist with breakout assessments.

Kali365 - EvilTokens Replica

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)

WIP Post-exploitation framework tailored for hypervisors.

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

DDoor - cross platform backdoor using dns txt records

a CLI for ephemeral penetration testing

Exploit for CVE-2015-6357 Cisco FireSIGHT Management Center Certificate Validation Vulnerability

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting