
ProxyLogon-CVE-2021-26855
RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

A fully featured Windows backdoor that uses email as a C&C server

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

C&C Botnet written in Python with fabric

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

A Golang implant that uses Slack as a command and control server

Automated 802.1x Bypass

Ping Exfiltration Command and Control (PiX-C2)

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

xll windows reverse shell

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Proof-of-concept exploit for Pi-Hole AdminLTE command injection (CVE-2019-13051) enabling remote root access via email field injection and cron-based…

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

Proofpoint Email Gateway: Low level authenticated user to admin RCE

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.