
phpsploit
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Cloud-native C2 framework using cloud storage as dead-drop communication channel

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

CVE-2020-1048 bypass: binary planting PoC

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…


Remote operations commands implemented using Beacon Object Files

Analysis of malware found on a server compromised via CVE-2025-55182, including obfuscated dropper, C2 communication, persistence mechanisms, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…