
Slackor
A Golang implant that uses Slack as a command and control server

A Golang implant that uses Slack as a command and control server

A tool for security professionals to access and interact with remote Microsoft Windows based systems.

Anonymously Reverse Shell over Tor Network using Hidden services without Portforwarding.

Powershell C2 Server and Implants

A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

AV evading cross platform Backdoor and Crypter Framework with a integrated lightweight webUI

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

DNS tunneling tool using PowerShell and Nslookup to exfiltrate data and deliver payloads via DNS TXT/MX records, bypassing Constrained Language Mode…

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…