
LOLBITS
** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…

** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…

Multiplayer pivoting solution

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.


Collection of beacon BOF written to learn windows and cobaltstrike

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Process injection alternative

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

A C2 post-exploitation framework

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

PowerShell scripts for communicating with a remote host.