
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

Simple (relatively) things allowing you to dig a bit deeper than usual.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Source Code Management Attack Toolkit

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

PoC-Malware-TTPs

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

macOS Initial Access Payload Generator

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

Powershell-C2

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

LSTAR - CobaltStrike 综合后渗透插件

PowerShell-based command and control framework using website-hosted payloads for persistent remote access and post-exploitation on Windows systems.