
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Various tips & tricks

Open-Source Remote Administration Tool For Windows C# (RAT)

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

Generate Gmail Emailing Keyloggers to Windows.

C2/post-exploitation framework

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A simple remote tool in C#.

ParadoxiaRat : Native Windows Remote access Tool.

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…