
Medusa
🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.


Payload Generation Framework

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

netshell features all in version 2 powershell

A python reverse shell that uses DNS as the c2 channel

DNS-Shell is an interactive Shell over DNS channel

🕳 godoh - A DNS-over-HTTPS C2

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload

windows api bug

CVE-2026-41096: Heap Overflow in the Windows DNS Client

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

CVE-2021-26295-POC 利用DNSlog进行CVE-2021-26295的漏洞验证。 使用 poc:将目标放于target.txt后运行python poc.py即可。(Jdk环境需<12,否则ysoserial无法正常生成有效载荷) exp:python exp.py…