
Pegasus-Gram
Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Script to steal passwords from ssh.

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Post-exploitation tool for hiding processes from monitoring applications

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Persistence by writing/reading shellcode from Event Log

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Automatic execution Payload From Windows By Path Users All Exploit Via File bashrc

Various tips & tricks

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…


In progress persistent download/upload/execution tool using Windows BITS.