
CPLDCOMTrigger
Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Python Remote Administration Tool (RAT)

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

C&C Botnet written in Python with fabric

An open-source Linux GUI-based Remote Access Tool developed in C# with a Python payload, intended for legitimate penetration testing and…

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info


PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Python script to efficiently find files on UNIX like file systems with specific properties (quicker than find)

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Weaponized Python exploit for CVE-2026-31431, chaining Linux kernel privilege escalation to a daemonized root reverse shell with full PTY, patching…

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)

Post-exploitation script leveraging .bashrc for persistent payload delivery and terminal manipulation, including destructive display and terminal…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

My python3 implementation of a Forward Shell

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…