
Empire
Empire is a PowerShell and Python post-exploitation agent.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies


Sigma detection rules for AI agent security monitoring

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.