
OneDrive-UDC2
OneDrive as a covert C2 transport for Cobalt Strike

OneDrive as a covert C2 transport for Cobalt Strike

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…


Multi-threaded, multi-os/platform (Linux/Windows) c2 server and Windows reverse TCP shell client both written in C.

A rust library that allows you to host the CLR and execute dotnet binaries.

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

CROSS PLATFORM REMOTE ACCESS TROJAN (RAT)

Windows local privilege escalation exploit abusing SeManageVolumePrivilege to grant full C:\ drive access and gain a SYSTEM shell via PrintConfig.dll…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Some Rust program I wrote while learning Malware Development

Reverse NTP remote access trojan in python, for penetration testers

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

Mac OS Trojan (RAT) made with love <3

remote code execute for redis4 and redis5


C++

PowerShell to Slack C2