
Adrenaline
C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

An interactive CLI application for interacting with authenticated Jupyter instances.

Control a system remotely via telegram

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Various Cobalt Strike BOFs

LSTAR - CobaltStrike 综合后渗透插件

SharpSploit is a .NET post-exploitation library written in C#

An evil RAT (Remote Administration Tool) for macOS / OS X.

iOS/macOS/Linux Remote Administration Tool