
PersistBOF
A BOF to automate common persistence tasks for red teamers

A BOF to automate common persistence tasks for red teamers

CVE-2025-8088-BUILDER

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler


A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Windows COM hijacking persistence tool with search, classic, Task Scheduler, and TreatAs modes. Available as .NET executable and Cobalt Strike BOF…

Windows tool that disables Driver Signature Enforcement by patching kernel variables, allowing unsigned drivers to load for testing and research.

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…