
Seatbelt
C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

WMI-based Windows remote execution tool for stealthy lateral movement, featuring AMSI bypass, file transfer, RID hijacking, firewall abuse, and event…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

An evil RAT (Remote Administration Tool) for macOS / OS X.

Abuse Exchange services via MAPI/HTTP or RPC/HTTP to enumerate users, create malicious mail rules, execute VBScript through Outlook forms/homepage,…

USB-based hardware attack tool using Arduino/Digispark to deploy Wi-Fi backdoors, harvest network history, and install persistent IP tracking on…

PowerShell-based tool that remotely queries WMI to locate hosts with high persistence survivability ratings, aiding red-team implant placement and…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

iOS/macOS/Linux Remote Administration Tool

A chromium extension exploitation toolkit

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploit for CVE-2026-58057 targeting Flowise Windows RCE via case-sensitive environment variable validation bypass. Supports reverse shell,…

Cobalt Strike BOFs for in-memory post-exploitation: Active Directory enumeration, clipboard capture, WiFi credential dump, port scan, and registry…

Assist reverse tcp shells in post-exploration tasks

Bash-based post-exploitation toolkit for pentesters, providing modular commands for privilege escalation, persistence, lateral movement, and…