
File-Tunnel
Tunnel TCP connections through a file

Tunnel TCP connections through a file

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

Windows RPC firewall that audits, detects, and blocks malicious remote procedure calls to prevent lateral movement, reconnaissance, and exploitation…

Bypass firewall for traffic forwarding using webshell

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

DejaVU - Open Source Deception Framework

Dominate the domain. Relay to royalty.

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Run Powershell without software restrictions.

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

Chisel new generation, written in rust. SSH under WSS with some customization.