
Cuteit
IP obfuscator made to make a malicious ip a bit cuter

IP obfuscator made to make a malicious ip a bit cuter

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

DNS over HTTPS targeted malware (only runs once)

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.

Adversary Emulation Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Crystal Palace Evasion kit for Sliver

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…