
Log4jUnifi
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

The perfect butler for pentesters, bug-bounty hunters and security researchers

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit

Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

A Netcat-style backdoor for pentesting and pentest exercises

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

Encrypted command‑and‑control (C2) research framework for cybersecurity education, red team labs, and secure client‑server communication experiments.