
CSSG
Cobalt Strike aggressor script for generating, formatting, and encrypting beacon shellcode with support for multiple exit methods, syscalls, and…

Cobalt Strike aggressor script for generating, formatting, and encrypting beacon shellcode with support for multiple exit methods, syscalls, and…

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)

Exploit script for CVE-2019-2618, a Weblogic arbitrary file upload vulnerability, with JSP webshell deployment and encrypted credential decryption.

A collection of scripts for dealing with Cobalt Strike beacons in Python

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

A Runtime Crypter in C for Linux ELF binaries.

Client-server tool for remotely loading and executing Java bytecode via ClassLoader and Reflect API, with ChaCha20 encryption and keepalive…

An open-source Linux GUI-based Remote Access Tool developed in C# with a Python payload, intended for legitimate penetration testing and…

Remote Windows keylogger with AES-256 encrypted keystroke exfiltration via configurable callback intervals and a companion Python server for log…

python2.7 script for JWT generation

This project for CVE-2019-18935

HTTP-based command and control server with end-to-end encryption, agent management, and a built-in web frontend for sending commands and viewing…

🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.

A PowerShell armoury for security guys and girls

JSON Web Token Hack Toolkit

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…