
Cooolis-ms
Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Cobalt Strike extension for post-exploitation persistence using SharpStay .NET assembly. Provides GUI-driven persistence via Registry keys, Scheduled…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

Linux bash script automation for metasploit

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.

My collection of metasploit auxiliary post-modules

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.


JavaScript for Automation (JXA) macOS agent


A cross-platform implant written in Nim

Port of Cobalt Strike's Process Inject Kit