
sliver
Adversary Emulation Framework

Adversary Emulation Framework

A simple remote tool in C#.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

List of Awesome CobaltStrike Resources

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

A framework for constructing self-spreading binaries

WORK IN PROGRESS. RAT written in C++ using Win32 API

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

A collection of tools for dealing with TrickBot

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)