
TornadoRevC2
Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

iOS/macOS/Linux Remote Administration Tool

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

Attacks for $5 or less using Arduino

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

A tool to abuse Exchange services

EGESPLOIT is a golang library for malware development

Bash post exploitation toolkit

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

An evil RAT (Remote Administration Tool) for macOS / OS X.

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

New generation of wmiexec.py

SharpSploit is a .NET post-exploitation library written in C#

LSTAR - CobaltStrike 综合后渗透插件

Various Cobalt Strike BOFs

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…