
SharpStay
.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

An information security preparedness tool to do adversarial simulation.

A simple C2 Framework written in modern C++

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Generate Payloads and Control Remote Machines. [Discontinued]

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

Powershell Persistence Locator

An open-source post-exploitation framework for students, researchers and developers.

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)