
Mystikal
macOS Initial Access Payload Generator

macOS Initial Access Payload Generator

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Creates invisible Windows accounts with administrative privileges via direct SAM manipulation and RID hijacking, bypassing standard user management…



Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

A native backdoor module for Microsoft IIS (Internet Information Services)


ABYSS C2 — HiSilicon DVR Exploit Framework (CVE-2020-25078). Educational IoT security research platform.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.


Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)