
lockjaw
Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Windows post-exploitation reconnaissance agent that collects system info, privileges, patches, defenses, network config, credentials, and persistence…

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Bash post exploitation toolkit

New generation of wmiexec.py

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

A chromium extension exploitation toolkit

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Source Code Management Attack Toolkit

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

DNS covert channel implant for Red Teams.

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Powershell Persistence Locator

Malicious WMI Events using PowerShell