
KittyStager
KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

the only php webshell you need.

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

The program is designed to obfuscate the shellcode.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)

Simple executable generator with encrypted shellcode.

Weblogic Upload Vuln(Need username password)-CVE-2019-2618

A collection of scripts for dealing with Cobalt Strike beacons in Python

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation


A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers

Decrypt GlobalProtect configuration and cookie files.