
BRC4-BOF-Artillery
Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

about CobaltStrike

PowerSploit - A PowerShell Post-Exploitation Framework

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for…

Crystal Palace Evasion kit for Sliver


Better Remote Access Trojan

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Malleable C2 profiles for Cobalt Strike

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

A simple, extensible C&C beaconing system.

Cisco ASA Software and ASDM Security Research

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

WIP Post-exploitation framework tailored for hypervisors.

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used
