
backdoorme
SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Windows DLL proxying tool for local and remote DLL hijacking via SMB and DCOM. Generates proxy DLL payloads with custom commands, supporting Kerberos…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

A native backdoor module for Microsoft IIS (Internet Information Services)

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

DLL Password Filter Implant with Exfiltration Capabilities

Python-based RAT with a web-based C2 server and cross-platform agent builder. Supports remote shell execution, file transfer, screenshot capture,…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

A tool to transform Chromium browsers into a C2 Implant

Lightweight C++ RAT for Windows with remote command execution via CMD/Powershell, keylogging, script execution, auto-install persistence, and…

Offensive Windows technique collection for escaping or bypassing Loader Lock to run arbitrary code from DllMain, enabling reliable DLL hijacking and…

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Tools for discovery and abuse of COM hijacks

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…