
Octopus
Open source pre-operation C2 server based on python and powershell

Open source pre-operation C2 server based on python and powershell

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

XSS payloads designed to turn alert(1) into P1

transform your payload.exe into one fake word doc (.ppt)

Hide your payload into .jpg file


Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

POC Exploit written in Ruby

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

Converts PE into a shellcode

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

Converts a EXE into DLL

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

Injects PHP payloads into JPEG images for web application exploitation, bypassing GD library image processing to achieve remote code execution.