
pentestcode
Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Abusing Azure services over C2

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

Golang tool designed to exfiltrate passwords found via the sshd and su services

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

C# toolkit for establishing and managing Windows persistence via registry keys, scheduled tasks, services, startup folders, KeePass configs, and…

Tool for Active Directory Certificate Services enumeration and abuse