
glimmer
Adversary emulation and C2 framework for security research

Adversary emulation and C2 framework for security research

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

A fileless reverse shell and C2 framework leveraging direct syscalls, proxy tunneling, and ChaCha20 encryption for AV evasion.

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

An in-memory minimal CPU for agnostic on-the-fly protocols creation

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

PowerSploit - A PowerShell Post-Exploitation Framework

List of Awesome CobaltStrike Resources

Venom is a library that meant to perform evasive communication using stolen browser socket

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…