
Bella
Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

This C# tool sprays for admin access over the entire domain

A SOCKS proxy for Citrix.

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Manipulating and Abusing Windows Access Tokens.

Infect Shared Files In Memory for Lateral Movement

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

Windows Remote Post Breach Tool via Telegram

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.