
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis
"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.


A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Sigma detection rules for AI agent security monitoring

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.


Empire is a PowerShell and Python post-exploitation agent.