
Empire
Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Offensive Software Exploitation Course

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST

A tool to transform Chromium browsers into a C2 Implant

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

A small x64 library to load dll's into memory.

Collection of bypass gadgets to extend and wrap ysoserial payloads

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…


macOS Initial Access Payload Generator