
Silverseal
Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)

CVE-2026-43499 GhostLock futex UAF LPE PoC for OPPO PCKM00 (SM6150) / Linux 4.14.180

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Tools for maintaining access to systems and proof-of-concept demonstrations.

Python alternative to Mimikatz lsadump::dcshadow

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Various tips & tricks

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

A simple embedded Linux backdoor.

A chromium extension exploitation toolkit