
Loki.Rat
Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

SkyRAT - Powershell Remote Administration Tool

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Code execution/injection technique using DLL PEB module structure manipulation

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

The DCERPC only printerbug.py version

Local SYSTEM auth trigger for relaying

My Notes about Penetration Testing

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

LSTAR - CobaltStrike Translated to EN

This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is…

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Miscellaneous Tools