
TripleCross
A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

Source Code Management Attack Toolkit

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

Automated Persistence and Lateral Movement using GCP Patch Management

Creates invisible Windows accounts with administrative privileges via direct SAM manipulation and RID hijacking, bypassing standard user management…


PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)


ParadoxiaRat : Native Windows Remote access Tool.

A BOF to automate common persistence tasks for red teamers

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

BlackLotus UEFI Windows Bootkit

Demonized Shell is an Advanced Tool for persistence in linux.

Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).