
OneDrive-UDC2
OneDrive as a covert C2 transport for Cobalt Strike

OneDrive as a covert C2 transport for Cobalt Strike

A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.

Notion as a platform for offensive operations

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

Collection of proof-of-concept Metasploit modules for exploitation and post-exploitation testing, providing custom payloads and auxiliary functions…

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

A cross platform C2/post-exploitation framework.

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Metasploit custom modules, plugins, resource script and.. awesome metasploit collection

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege