
khaos-c2
KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Penetration testing framework with AI-driven decision engine

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

DCOM in memory and fileless lateral movement techniques through .Net deserilization

BOF POC of the DSCourier project / invoking WinGet via COM

Tools and Techniques for Red Team / Penetration Testing

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

Local privilege escalation exploit for CVE-2025-62676.

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

CVE-2025-33073

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Code execution/injection technique using DLL PEB module structure manipulation

Proof-of-concept exploit for CVE-2024-57394: low-privilege file restoration to System32 enabling DLL hijacking and local privilege escalation to…