
C3
Framework for rapid prototyping of custom command-and-control channels with integration into Cobalt Strike and support for esoteric C2 transports via…

Framework for rapid prototyping of custom command-and-control channels with integration into Cobalt Strike and support for esoteric C2 transports via…

Port listener and reverse shell tool with interactive mode, command history, and tab completion. Supports Linux, macOS, and Windows for penetration…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

A delicious, but malicious SSL-VPN server 🌮

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

Tor transport bridge for Sliver C2 - anonymous command and control

Agent dispatcher that launches security tools and sends structured results to the Faraday platform. Supports custom executors and integrates with…

Python-based proof-of-concept exploit for CVE-2022-34718, a remote code execution vulnerability in IPv6 on Windows, using Scapy to craft and send…

This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted…

Proof-of-concept exploit for CVE-2026-18649, a remote unauthenticated denial-of-service in GStreamer's rtph264depay via crafted H.264 RTP FU-A…

Proof-of-concept exploit for CVE-2024-38063, generating fragmented IPv6 packets with malicious destination options to trigger denial-of-service on…

Proof-of-concept exploit for CVE-2018-4407, an ICMP denial-of-service vulnerability affecting Apple iOS and macOS devices. Sends crafted ICMP packets…

Exploit tool for CVE-2018-10933 libSSH authentication bypass, enabling remote shell access without credentials using Python scripts and optional fake…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

Python-based exploit for CVE-2024-38063 targeting Windows IPv6 vulnerability. Automates network interface detection, packet crafting, and…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…