
rootkit
Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

C# tool to retrieve LAPS passwords from Active Directory via LDAP, designed for in-memory execution within Cobalt Strike sessions using…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

More examples using the Impacket library designed for learning purposes.

C# tool for establishing Windows persistence via multiple techniques including scheduled tasks, WMI events, startup folders, and registry hijacking,…

The SteaLinG is an open-source penetration testing framework designed for social engineering

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.