
CdpSvcLPE
Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

A BOF to automate common persistence tasks for red teamers

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

DNS-based post-exploitation agent with persistence mechanisms, pseudo-interactive shell, and shellcode injection for covert command and control.

Persistence by writing/reading shellcode from Event Log

Tools for maintaining access to systems and proof-of-concept demonstrations.

Proof-of-concept framework for CVE-2025-24252 and CVE-2025-24132, providing mDNS crash trigger and heap overflow reverse shell with multiple payload…

Execute a payload at each right click on a file/folder in the explorer menu for persistence

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

Generate proxy DLLs that forward exports to a target DLL while loading a user-defined secondary DLL, enabling DLL hijacking and side-loading for red…

CROSS PLATFORM REMOTE ACCESS TROJAN (RAT)

Proof-of-concept for loading kernel drivers via NtLoadDriver and SC Manager APIs, designed for adversarial tradecraft demonstrations and RAT payload…

Post-exploitation bind and backconnect shell with interactive TTY, process cloaking, anti-debugging, and automatic privilege escalation. Generates…

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

C# stub for njRAT remote access trojan, fixed for PowerShell compatibility. Enables remote control, command execution, and persistence on compromised…