
Empire
Empire is a PowerShell and Python post-exploitation agent.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Adversary simulation and Red teaming platform with AI

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Autonomous Hacking Agent for Red Team

An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Tool to remotely dump secrets from the Windows registry

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

A C2 post-exploitation framework

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.


RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…