
TornadoRevC2
Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Source Code Management Attack Toolkit

Various Cobalt Strike BOFs

New generation of wmiexec.py

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

A chromium extension exploitation toolkit

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

LSTAR - CobaltStrike 综合后渗透插件

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Powershell Persistence Locator

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

iOS/macOS/Linux Remote Administration Tool

Malicious WMI Events using PowerShell

A tool to abuse Exchange services

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

An evil RAT (Remote Administration Tool) for macOS / OS X.