
Chisel-Strike
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.

A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

A fully featured Windows backdoor that uses Gmail as a C&C server

Modular post-exploitation framework using Dropbox as a covert C2 channel, with PowerShell modules, keylogging, screenshot capture, and process…

Python-based reverse shell with TLS encryption, file transfer, UDP flooding/spoofing, plugin system, and RESTful API for post-exploitation and red…

Automates Meterpreter payload generation with SSL certificate validation, supporting staged/stageless builds, HTA delivery, and post-exploitation…

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

A stealthy Python based Windows backdoor that uses Github as a command and control server

Reverse shell generator written in Python 3.

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

Community payload loaders, scripts, and configurations for Brute Ratel C4, supporting red team command-and-control operations and payload deployment.

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

DNS-based post-exploitation agent with persistence mechanisms, pseudo-interactive shell, and shellcode injection for covert command and control.

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.