
SliverMirage
Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

This is a modified version of the original CVE-2024-30088 exploit, adapted to work in non-interactive environments (WinRM).

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Apply a divide and conquer approach to bypass EDRs

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

.NET assembly loader with patchless AMSI and ETW bypass

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Python alternative to Mimikatz lsadump::dcshadow

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

An automated SMB relay exploitation script.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

PHP shells that work on Linux OS, macOS, and Windows OS.

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

WORK IN PROGRESS. RAT written in C++ using Win32 API

Work in Progress. RAT written in C++ using wxWidgets

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Make CVE-2020-0668 exploit work for version < win10 v1903 and version >= win10 v1903

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning,…