
rosemary
Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…


Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

This C# tool sprays for admin access over the entire domain

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

WORK IN PROGRESS. RAT written in C++ using Win32 API

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Exploit for CVE-2014-4210 targeting WebLogic deserialization, with post-exploitation features including ransomware deployment, C2 integration, and…

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.