
cyanide
Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Open-source multi-purpose remote access tool for Microsoft Windows

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration…

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Educational remote administration tool for learning RAT concepts, featuring file transfer, screenshot capture, system monitoring, and webcam access…

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

EXOCET - AV-evading, undetectable, payload delivery tool

NetRipper - Smart traffic sniffing for penetration testers

We developed GRAT2 Command & Control (C2) project for learning purpose.

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…