
DNSStager
Hide your payload in DNS

Hide your payload in DNS

🕳 godoh - A DNS-over-HTTPS C2

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Payload Generation Framework

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

netshell features all in version 2 powershell

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

Execute commands on Windows via malicious TXT DNS records

DNS-Shell is an interactive Shell over DNS channel

A python reverse shell that uses DNS as the c2 channel

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload

windows api bug