
Stardust
A modern 32/64-bit position independent implant template

A modern 32/64-bit position independent implant template

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

Python botnet and backdoor

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

PowerShell ReverseTCP Shell - Framework

A fully featured backdoor that uses Twitter as a C&C server

A unique technique to execute binaries from a password protected zip

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

UAC bypass for x64 Windows 7 - 11

Various webshells. We accept pull requests for additions to this collection.

A set of fully-undetectable process injection techniques abusing Windows Thread Pools


a open source remote administrator tool

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

Threadless Process Injection using remote function hooking.

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️