
merlin
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

A unified console to perform the "kill chain" stages of attacks.

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

This aggressor script uses a beacon's note field to indicate the health status of a beacon.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Extending of metasploit-framework

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

generate CobaltStrike's cross-platform payload