
ContextMenuHijack
Execute a payload at each right click on a file/folder in the explorer menu for persistence

Execute a payload at each right click on a file/folder in the explorer menu for persistence

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

Tools for maintaining access to systems and proof-of-concept demonstrations.

Powershell Persistence Locator

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

CVE-2020-1048 bypass: binary planting PoC

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

A host based IDS written in C# Targetted at Metasploit

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.


C2/post-exploitation framework