
Network-Filesystem-Forensics
Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

Establish secure remote access to a machine with interactive shell, file transfer, and web proxy over end-to-end encrypted peer-to-peer WebRTC, using…

This tool is used to map out the network data flow to help penetration testers identify potentially valuable targets.

Ping Exfiltration Command and Control (PiX-C2)

Application-scoped Windows network brownouts in native C and BOF form

NetRipper - Smart traffic sniffing for penetration testers

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.