
dns-black-cat
Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

Bash simulator to control a server using PHP system functions.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Generates header/ASM files for direct Windows system calls to bypass user-mode API hooks used by AV/EDR products, enabling stealthy red team…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

HTTP-based remote access tool with DLL injection, process hollowing, and system hooking for persistent control, screen monitoring, file exfiltration,…

A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

Python-based reverse shell with TLS encryption, file transfer, UDP flooding/spoofing, plugin system, and RESTful API for post-exploitation and red…

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

Single-file Windows exploit for CVE-2019-0708 (BlueKeep) that executes a reverse shell with SYSTEM privileges via RDP, statically compiled with…

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

Proof-of-concept exploit for CVE-2025-8088 WinRAR path traversal vulnerability. Generates malicious RAR archives using alternate data streams to…

A payload delivery system which embeds payloads in an executable's icon file!

Stealth-enabled keystroke and visual intelligence gathering system for authorized red team operations. Features persistent surveillance, C2 tunnel,…

Windows persistence technique using AddMonitor to load a malicious DLL with SYSTEM privileges, enabling remote C2 via Meterpreter.

Proof-of-concept for Apache Struts2 S2-061 (CVE-2020-17530) demonstrating OGNL injection leading to remote code execution, with SSRF and system…