
Stracciatella
OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

PowerShell wrapper bundling 50+ C# offensive security tools for post-exploitation, privilege escalation, credential dumping, lateral movement, and…

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

Undetectable Windows Payload Generation

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Starkiller is a Frontend for PowerShell Empire.

Excalibur is an Eternalblue exploit payload based "Powershell" for the Bashbunny project.

PowerSploit - A PowerShell Post-Exploitation Framework


A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs.

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

PowerShell Runspace Post Exploitation Toolkit

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)

Powershell C2 Server and Implants

Automated Tactics Techniques & Procedures

CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and…