
ChromeAlone
A tool to transform Chromium browsers into a C2 Implant

A tool to transform Chromium browsers into a C2 Implant

A light-weight first-stage C2 implant written in Nim (and Rust).

Hershell is a simple TCP reverse shell written in Go.

🕳 godoh - A DNS-over-HTTPS C2

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

CVE-2019-2725 命令回显

Weblogic CVE-2020-14882 unauthorized RCE exploit with patch bypass, command execution, and webshell deployment for penetration testing.

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.


Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.

A fully featured Windows backdoor that uses Gmail as a C&C server

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Hide your payload into .jpg file