
Empire
Empire is a PowerShell and Python post-exploitation agent.

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Open source pre-operation C2 server based on python and powershell

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

A C2 post-exploitation framework

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

A WebDAV PROPFIND C2 tool

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Weblogic Unrestricted File Upload