
C4
Cyberdelia, a Collection of Command and Control frameworks

Cyberdelia, a Collection of Command and Control frameworks

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

GitHub Self-Hosted Runner Enumeration and Attack Tool

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

RedEye is a visual analytic tool supporting Red & Blue Team operations

A stealthy Python based Windows backdoor that uses Github as a command and control server

Github as C2 Demonstration , free API = free C2 Infrastructure

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

Proof-of-concept lab demonstrating command injection in GitHub Actions workflow dispatch (CVE-2026-39866). Runs vulnerable and patched versions…

Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run,…

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

OS Command Injection in Health Check → Remote Code Execution