
emp3r0r
Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Tunnel TCP connections through a file

Proof-of-concept exploit for CVE-2026-0828, a BYOVD vulnerability in Safetica ProcessMonitorDriver.sys allowing unprivileged termination of…

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Dominate the domain. Relay to royalty.

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

Chisel new generation, written in rust. SSH under WSS with some customization.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

DejaVU - Open Source Deception Framework

Windows RPC firewall that audits, detects, and blocks malicious remote procedure calls to prevent lateral movement, reconnaissance, and exploitation…

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

LSTAR - CobaltStrike Translated to EN

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop