
Empire
Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

A third-party Gopher Assassin for the Havoc Framework.

Single executable reverse SOCKS5 proxy written in Golang.

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry


Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

shouganaiyo-loader is a cross-platform Frida-based Node.js command-line tool that forces Java processes to load a Java/JVMTI agent regardless of…

Proof of concept about the privilege escalation flaw identified in Google's Osconfig

JavaScript for Automation (JXA) macOS agent

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Post Exploitation agent which uses a browser to do C2 operations.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.