
phpsploit
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Modular command-and-control framework abusing Microsoft Outlook's Home Page feature for stealthy persistence, remote access, and post-exploitation.

This repository contains a list of tools that may be useful for consultants performing penetration testing engagements.

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

A cross-platform implant written in Nim

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE…

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Extendable pentesting framework for automotive UDS interfaces, enabling reproducible scans, diagnostic trouble code reading, and post-processing via…

Mythic C2 agent targeting Linux and Windows hosts written in Rust

Open-source C2 integration framework providing a unified web interface for managing multiple command-and-control instances, listeners, agents, and…

Automate Metasploit scanning and exploitation

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

How To Install Metasploit-Table on the Android Termux

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…