
React2Shell
React2Shell - CVE-2025-66478 RCE Exploit

React2Shell - CVE-2025-66478 RCE Exploit

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

Covenant is a collaborative .NET C2 framework for red teamers.

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

A post exploitation framework designed to operate covertly on heavily monitored environments

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…


DeimosC2 is a Golang command and control framework for post-exploitation.

link is a command and control framework written in rust

A C# Command & Control framework

** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…

C# C2 Framework centered around Stage 1 operations

Nimbo-C2 is yet another (simple and lightweight) C2 framework

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

Open-source C2 integration framework providing a unified web interface for managing multiple command-and-control instances, listeners, agents, and…